CVE-2023-39982: MXsecurity Hardcoded Credential
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-39982?
CVE-2023-39982 is a vulnerability in MXsecurity versions prior to v1.0.1 that puts the confidentiality and integrity of SSH communications at risk.
How does CVE-2023-39982 affect the affected device?
CVE-2023-39982 affects the affected device by exposing it to potential man-in-the-middle attacks due to a hard-coded SSH host key.
What is the severity level of CVE-2023-39982?
CVE-2023-39982 has a severity level of high, with a CVSS score of 5.9.
How can I fix CVE-2023-39982?
To fix CVE-2023-39982, update your MXsecurity software to version 1.0.1 or higher.
Where can I find more information about CVE-2023-39982?
You can find more information about CVE-2023-39982 in the Moxa Security Advisory at https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230403-mxsecurity-series-multiple-vulnerabilities.