CVE-2023-33235
published 2023-05-22CVE-2023-33235: MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.46%
70.4th percentile
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxsecurity | — | — |
| moxa | mxsecurity_series | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-33235 is exploited via the SSH CLI program on Moxa MXsecurity v1.0; monitor for SSH sessions that attempt to break out of the restricted shell and execute arbitrary commands ↗
- →Affected product is Moxa MXsecurity Series Software v1.0 only; presence of this version on network-accessible devices indicates exposure to CVE-2023-33235 ↗
- →The vulnerability requires prior authorization/high-privilege access (CVSS PR:H) over the network (AV:N); alert on privileged SSH logins to MXsecurity devices followed by anomalous shell activity ↗
- ·No known public exploits specifically target CVE-2023-33235 at time of advisory publication; exploitation requires prior high-privilege authorization ↗
- ·CVE-2023-33235 (Command Injection, CVSS 7.2) is distinct from the companion CVE-2023-33236 (Hard-Coded Credentials, CVSS 9.8); the hard-coded credentials issue may be used as a stepping stone to gain the authorization required to exploit CVE-2023-33235 ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXsecurity Series
cisa_ics·2023-05-25·CVSS 7.2
[HIGH] Moxa MXsecurity Series
ICS Advisory
##
Moxa MXsecurity Series
Release DateMay 25, 2023
Alert CodeICSA-23-145-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXsecurity Series
- Vulnerabilities: Command Injection and Use of Hard-Coded Credentials
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an unauthorized user to bypass authentication or to execute arbitrary commands on the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Moxa reports these vulnerabilities affect the following MXsecurity Series:
- MXsecurity Series: Software v1.0
## 3.2 VULNERABILITY OVERVIEW
3.2.1 COMMAND INJECTION CWE-77
A remote attacker, who has gained authorization privileges, cou
GHSA
GHSA-cx3c-2jcw-jmfg: MXsecurity version 1
ghsa_unreviewed·2023-05-22
CVE-2023-33235 [HIGH] CWE-77 GHSA-cx3c-2jcw-jmfg: MXsecurity version 1
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-22
Published