HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-39982

CVSS 7.5v3.1pub. 2023-09-02upd. 2024-11-21

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Moxa Mxsecurity

    APP
    Moxa
    ≤ 1.0.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-39979CRITICAL9.8PL ✓same product

Podatność Auth Bypass w Moxa MXsecurity — niewystarczająca losowość uwierzytelnienia

CVE-2023-33236CRITICAL9.8PL ✓same product

Moxa MXsecurity – hardcoded credentials umożliwiające bypass uwierzytelnienia

CVE-2023-39981HIGH7.5same product

A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1...

CVE-2023-39980HIGH7.1same product

A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MX...

CVE-2023-33235HIGH7.2same product

MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported ...