PT-2023-4605 · Unknown · Tn-5900 Series

CVE-2023-34215

·

Published

2023-08-16

·

Updated

2024-10-28

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TN-5900 Series firmware versions prior to v3.3
Description The issue stems from insufficient input validation and improper authentication in the certification-generation function. This could potentially allow malicious users to execute remote code on affected devices. The vulnerability is related to errors in processing input data in the certification-generation function.
Recommendations For TN-5900 Series firmware versions prior to v3.3, update to a version later than v3.3 to resolve the issue. As a temporary workaround, consider restricting access to the certification-generation function until a patch is available. Avoid using the certification-generation function with untrusted input until the issue is resolved.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05012
CVE-2023-34215

Affected Products

Tn-5900 Series