CVE-2023-34217: Second Order Command-injection Vulnerability in the Certificate-delete Function
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-34217?
CVE-2023-34217 is a command-injection vulnerability in TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior.
What is the severity of CVE-2023-34217?
The severity of CVE-2023-34217 is high with a CVSS score of 8.1.
How does CVE-2023-34217 occur?
CVE-2023-34217 occurs due to insufficient input validation in the certificate-delete function of the affected firmware versions.
What is the potential impact of CVE-2023-34217?
CVE-2023-34217 could potentially allow malicious users to execute arbitrary commands on the affected devices.
How can I fix CVE-2023-34217?
To fix CVE-2023-34217, it is recommended to update the TN-4900 Series firmware to version v1.2.5 or later and the TN-5900 Series firmware to version v3.4 or later.