CVE Vulnerabilities

CVE-2023-39979

Small Space of Random Values

Published: Sep 02, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

Weakness

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Affected Software

Name Vendor Start Version End Version
Mxsecurity Moxa * 1.1.0 (excluding)

Potential Mitigations

References