CVE-2023-34213: Second Order Command-injection Vulnerability in the Key-generation Function
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-34213?
CVE-2023-34213 is a command-injection vulnerability in TN-5900 Series firmware versions v3.3 and prior.
How severe is CVE-2023-34213?
CVE-2023-34213 has a severity rating of 9.8 (critical).
How does CVE-2023-34213 work?
CVE-2023-34213 is caused by insufficient input validation and improper authentication in the key-generation function of TN-5900 Series firmware, allowing potential remote code execution.
Which software versions are affected by CVE-2023-34213?
TN-5900 Series firmware versions v3.3 and prior are vulnerable to CVE-2023-34213.
How can I mitigate CVE-2023-34213?
To mitigate CVE-2023-34213, it is recommended to update the TN-5900 Series firmware to a version higher than v3.3.