Sensitive Information Exposure Risk Due to Cleartext Credentials Storage
CVE-2024-6785
7.1HIGH
Key Information:
- Vendor
- Moxa
- Vendor
- CVE Published:
- 21 September 2024
Summary
A vulnerability in the Moxa MXView and MXView One Central Manager series allows for credential storage in cleartext within the configuration file. This may enable an attacker with local access rights to read or modify the configuration file. The implications of this vulnerability could lead to the exposure of sensitive information and potential misuse of the service, threatening the overall security posture of affected systems.
Affected Version(s)
MXview One Central Manager Series 0 < 1.0.0
MXview One Series 0 < 1.3.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Noam Moshe of Claroty Research - Team82