CVE-2023-33237: Authentication Bypass Without Administrator Privilege
TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only high-privileged APIs are allowed This presents a potential risk of unauthorized exploitation by malicious actors.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-33237.
What is the severity of CVE-2023-33237?
The severity of CVE-2023-33237 is high with a severity value of 8.8.
What software versions are affected by CVE-2023-33237?
TN-5900 Series firmware version v3.3 and prior are affected by CVE-2023-33237.
How does CVE-2023-33237 occur?
CVE-2023-33237 occurs due to inadequate authentication measures implemented in the web API handler of TN-5900 Series firmware version v3.3 and prior.
Is there a fix available for CVE-2023-33237?
Please refer to the Moxa Security Advisory for remediation steps and firmware updates for CVE-2023-33237.