CVE-2023-34217
published 2023-08-17CVE-2023-34217: TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability…
PriorityP347high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.38%
29.8th percentile
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | edr-g9010_series | 1.0 – 2.1 | — |
| moxa | edr-g902_series | 1.0 – 5.7.17 | — |
| moxa | edr-g903_series | 1.0 – 5.7.15 | — |
| moxa | nat-102_series | 1.0 – 1.0.3 | — |
| moxa | tn-4900_firmware | <= 1.2.4 | — |
| moxa | tn-4900_series | 1.0 – 1.2.4 | — |
| moxa | tn-5900_firmware | <= 3.3 | — |
| moxa | tn-5900_series | 1.0 – 3.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-17
Published