Sensitive Information Exposure Risk Due to Cleartext Credentials Storage
CVE-2024-6785

7.1HIGH

Key Information:

Vendor
Moxa
Vendor
CVE Published:
21 September 2024

Summary

A vulnerability in the Moxa MXView and MXView One Central Manager series allows for credential storage in cleartext within the configuration file. This may enable an attacker with local access rights to read or modify the configuration file. The implications of this vulnerability could lead to the exposure of sensitive information and potential misuse of the service, threatening the overall security posture of affected systems.

Affected Version(s)

MXview One Central Manager Series 0 < 1.0.0

MXview One Series 0 < 1.3.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noam Moshe of Claroty Research - Team82
.