CVE Published: 22/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Moxa |
Vendor: Moxa |
Product: MXsecurity Series Status : PUBLISHED
CVE-2023-33236 Description
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H