Insufficiently Protected Credentials in Mobotix Control Center Software
CVE-2022-30018
8.8HIGH
What is CVE-2022-30018?
The Mobotix Control Center (MxCC) version 2.5.4.5 contains a significant vulnerability due to its method of credential storage. It stores passwords in a recoverable format within the MxCC.ini configuration file. This design flaw allows attackers or unauthorized users with access to the machine to easily retrieve these stored passwords, potentially gaining administrator-level access to the software. Consequently, this access not only exposes the application's sensitive functionalities but also allows intruders to view and manipulate recorded content and recording locations.