First published: Wed Jul 05 2023(Updated: )
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.
Credit: psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Tn-5900 Firmware | <=3.3 | |
Moxa TN-5900 |
Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below: * TN-5900 Series: Please upgrades to firmware version 3.4 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3336 is a user enumeration vulnerability in TN-5900 Series version 3.3 and prior versions.
A remote attacker can exploit CVE-2023-3336 by determining whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.
TN-5900 Series version 3.3 and prior versions are affected by CVE-2023-3336.
CVE-2023-3336 has a severity rating of medium (5.3).
To fix CVE-2023-3336, it is recommended to update TN-5900 Series firmware to a version that is not vulnerable.