CVE-2023-34215: Second Order Command-injection Vulnerability in the Certificate-generation Function
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the certification-generation function, which could potentially allow malicious users to execute remote code on affected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is vulnerability CVE-2023-34215?
Vulnerability CVE-2023-34215 is a command-injection vulnerability in the TN-5900 Series firmware versions v3.3 and prior.
How severe is vulnerability CVE-2023-34215?
Vulnerability CVE-2023-34215 has a severity rating of 9.8 (critical).
What is the affected software for vulnerability CVE-2023-34215?
The affected software for vulnerability CVE-2023-34215 is the Moxa TN-5900 firmware versions up to and including v3.3.
What is the CWE ID for vulnerability CVE-2023-34215?
The CWE IDs associated with vulnerability CVE-2023-34215 are 20 (Improper Input Validation) and 77 (Improper Neutralization of Special Elements used in a Command).
How do I fix vulnerability CVE-2023-34215?
To fix vulnerability CVE-2023-34215, it is recommended to update the TN-5900 Series firmware to a version above v3.3 that addresses the command-injection vulnerability.