VYPR
Critical severity9.8NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026

CVE-2023-33282

CVE-2023-33282

Description

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Marvalglobal/Msm2 versions
    cpe:2.3:a:marvalglobal:msm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:marvalglobal:msm:*:*:*:*:*:*:*:*range: <=14.19.0.12476
    • cpe:2.3:a:marvalglobal:msm:15.0:*:*:*:*:*:*:*
  • Marval/MSMdescription
  • Marval/MSMllm-create
    Range: <=14.19.0.12476, <15.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.