CVE-2023-33236
published 2023-05-22CVE-2023-33236: MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
58.4th percentile
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxsecurity | — | — |
| moxa | mxsecurity_series | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-33236 exploits hard-coded credentials in Moxa MXsecurity Series Software v1.0 to craft arbitrary JWT tokens and bypass authentication for web-based APIs. Detect unauthorized or anomalous JWT token usage against MXsecurity web APIs, especially from unauthenticated or unexpected sources. ↗
- →The vulnerability is remotely exploitable with no privileges required (CVSS PR:N) and low attack complexity (AC:L), meaning exploitation attempts may appear as normal unauthenticated API requests. Monitor MXsecurity web API endpoints for authentication bypass attempts. ↗
- →Scope detection to Moxa MXsecurity Series devices running Software v1.0 specifically, as that is the only confirmed affected version. ↗
- ·No public exploits were known at the time of advisory publication; exploitation indicators may be limited to anomalous API authentication patterns rather than known malicious signatures. ↗
- ·The hard-coded credential is embedded in the product itself (CWE-798); the specific credential value or JWT secret is not publicly disclosed in these sources, limiting the ability to write a precise signature-based detection rule. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXsecurity Series
cisa_ics·2023-05-25·CVSS 7.2
[HIGH] Moxa MXsecurity Series
ICS Advisory
##
Moxa MXsecurity Series
Release DateMay 25, 2023
Alert CodeICSA-23-145-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXsecurity Series
- Vulnerabilities: Command Injection and Use of Hard-Coded Credentials
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an unauthorized user to bypass authentication or to execute arbitrary commands on the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Moxa reports these vulnerabilities affect the following MXsecurity Series:
- MXsecurity Series: Software v1.0
## 3.2 VULNERABILITY OVERVIEW
3.2.1 COMMAND INJECTION CWE-77
A remote attacker, who has gained authorization privileges, cou
GHSA
GHSA-r6wg-6486-p79w: MXsecurity version 1
ghsa_unreviewed·2023-05-22
CVE-2023-33236 [CRITICAL] CWE-798 GHSA-r6wg-6486-p79w: MXsecurity version 1
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-22
Published