CVE-2023-39983: MXsecurity Register Database Pollution
Published Sep 2, 2023
·Updated
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.
Affected Software
1 affected component
MOXA Mxsecurity<=1.0.1
Remediation
Information
Moxa has developed appropriate solution to address the vulnerability. The solution for affected product is shown below.
* MXsecurity: Please upgrade to software v1.1.0 or higher.
Event History
Sep 2, 2023
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-39983.
2
What is the affected software for this vulnerability?
The affected software is Moxa Mxsecurity version up to and including 1.0.1.
3
What is the severity of CVE-2023-39983?
The severity of CVE-2023-39983 is medium with a CVSS score of 5.3.
4
How does CVE-2023-39983 pose a risk?
CVE-2023-39983 poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI.
5
How can an attacker exploit CVE-2023-39983?
An unauthenticated remote attacker can exploit CVE-2023-39983 by registering or adding devices via the nsm-web application.