CVE-2023-39979: MXsecurity Authentication Bypass
Published Sep 2, 2023
·Updated
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.
Affected Software
1 affected component
MOXA Mxsecurity<1.1.0
Remediation
Information
Moxa has developed appropriate solution to address the vulnerability. The solution for affected product is shown below.
* MXsecurity: Please upgrade to software v1.1.0 or higher.
Event History
Sep 2, 2023
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-39979?
CVE-2023-39979 is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker if the web service authenticator has insufficient random values.
3
What is the severity of CVE-2023-39979?
The severity of CVE-2023-39979 is critical with a CVSS score of 9.8.
4
What is the affected software of CVE-2023-39979?
The affected software is MXsecurity versions prior to 1.0.1.
5
How can I fix CVE-2023-39979?
To fix CVE-2023-39979, it is recommended to update MXsecurity to version 1.0.1 or above.