First published: Sat Sep 02 2023(Updated: )
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.
Credit: psirt@moxa.com psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Mxsecurity | <=1.0.1 |
Moxa has developed appropriate solution to address the vulnerability. The solution for affected product is shown below. * MXsecurity: Please upgrade to software v1.1.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-39983.
The affected software is Moxa Mxsecurity version up to and including 1.0.1.
The severity of CVE-2023-39983 is medium with a CVSS score of 5.3.
CVE-2023-39983 poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI.
An unauthenticated remote attacker can exploit CVE-2023-39983 by registering or adding devices via the nsm-web application.