cbcvebase.
CVE-2023-33235
published 2023-05-22

CVE-2023-33235: MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.46%
70.4th percentile
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.

Affected

2 ranges
VendorProductVersion rangeFixed in
moxamxsecurity
moxamxsecurity_series

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-33235 is exploited via the SSH CLI program on Moxa MXsecurity v1.0; monitor for SSH sessions that attempt to break out of the restricted shell and execute arbitrary commands
  • Affected product is Moxa MXsecurity Series Software v1.0 only; presence of this version on network-accessible devices indicates exposure to CVE-2023-33235
  • The vulnerability requires prior authorization/high-privilege access (CVSS PR:H) over the network (AV:N); alert on privileged SSH logins to MXsecurity devices followed by anomalous shell activity
  • ·No known public exploits specifically target CVE-2023-33235 at time of advisory publication; exploitation requires prior high-privilege authorization
  • ·CVE-2023-33235 (Command Injection, CVSS 7.2) is distinct from the companion CVE-2023-33236 (Hard-Coded Credentials, CVSS 9.8); the hard-coded credentials issue may be used as a stepping stone to gain the authorization required to exploit CVE-2023-33235
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.