First published: Thu Aug 17 2023(Updated: )
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.
Credit: psirt@moxa.com psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Tn-5900 Firmware | <=3.3 | |
Moxa TN-5900 | ||
Moxa Tn-4900 Firmware | <=1.2.4 | |
Moxa Tn-4900 |
Moxa has developed appropriate solution to address the vulnerability. The solution for affected products is shown below: * * TN-4900 Series: Please upgrade to firmware v3.0 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/en-50155-routers/tn-5900-series#resources * TN-5900 Series: Please upgrade to firmware v3.4 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/en-50155-routers/tn-5900-series#resources * EDR-G902 Series: Please upgrade to firmware v5.7.21 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g902-series * EDR-G903 Series: Please upgrade to firmware v5.7.21 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g903-series#resources * EDR-G9010 Series: Please upgrade to firmware v3.0 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g9010-series#resources * NAT-102 Series: Please upgrade to firmware v1.0.5 or higher. https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/nat-102-series#resources
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34217 is a command-injection vulnerability in TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior.
The severity of CVE-2023-34217 is high with a CVSS score of 8.1.
CVE-2023-34217 occurs due to insufficient input validation in the certificate-delete function of the affected firmware versions.
CVE-2023-34217 could potentially allow malicious users to execute arbitrary commands on the affected devices.
To fix CVE-2023-34217, it is recommended to update the TN-4900 Series firmware to version v1.2.5 or later and the TN-5900 Series firmware to version v3.4 or later.