CVE-2023-39982 HIGH

CVE-2023-39982: MXsecurity Hardcoded Credential

Vendor Moxa
Product MXsecurity Series
Weakness CWE-321
Published September 2, 2023
Last update October 28, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.

Key dates

02Disclosure timeline

September 2, 2023 CVE published
October 28, 2024 Record updated