CVE-2023-33236

CRITICAL

MXsecurity 1.0 - Hardcoded Credential Bypass via JWT Token Crafting

Title source: llm
STIX 2.1

Description

MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 19.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
moxa/mxsecurity 1.0
Published May 22, 2023
Tracked Since Feb 18, 2026