Critical severity9.8NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2023-33282
CVE-2023-33282
Description
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:marvalglobal:msm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:marvalglobal:msm:*:*:*:*:*:*:*:*range: <=14.19.0.12476
- cpe:2.3:a:marvalglobal:msm:15.0:*:*:*:*:*:*:*
- Marval/MSMdescription
Patches
Vulnerability mechanics
References
2- www.cyberskydd.se/cve/2023/CVE-2023-33282.htmlnvdExploitThird Party Advisory
- marvalglobal.com/software/nvdProduct
News mentions
0No linked articles in our index yet.