TN-5900 Series User Enumeration Vulnerability
Published Jul 5, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.61%
Description
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enable a brute force attack with valid users.
Affected products
-
Affected
- ≥ 1.0, ≤ 3.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Moxa | TN-5900 Series | unaffected | Affected
|
- ≤ 3.3
-
Affected
- ≥ 1.0, ≤ 3.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Moxa | n/a | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below: * TN-5900 Series: Please upgrades to firmware version 3.4 or later.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44004 Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230401-tn-5900-series-user-enumeration-vulnerability vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44004 | Advisory | |
| https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230401-tn-5900-series-user-enumeration-vulnerability | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data