CVE-2023-3336: TN-5900 Series User Enumeration Vulnerability
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Moxa TN-5900 Series firmwareto a version that resolves this vulnerability.Fixed in 3.4
Event History
Frequently Asked Questions
What is CVE-2023-3336?
CVE-2023-3336 is a user enumeration vulnerability in TN-5900 Series version 3.3 and prior versions.
How can a remote attacker exploit CVE-2023-3336?
A remote attacker can exploit CVE-2023-3336 by determining whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.
Which software versions are affected by CVE-2023-3336?
TN-5900 Series version 3.3 and prior versions are affected by CVE-2023-3336.
What is the severity of CVE-2023-3336?
CVE-2023-3336 has a severity rating of medium (5.3).
How can I fix CVE-2023-3336?
To fix CVE-2023-3336, it is recommended to update TN-5900 Series firmware to a version that is not vulnerable.