Vulnerability in MQTT Allowes Arbitrary File Reading

CVE-2024-6786
6.5MEDIUM

Key Information

Vendor
Moxa
Status
Mxview One Series
Vendor
CVE Published:
21 September 2024

Summary

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.

Affected Version(s)

MXview One Series < 1.4

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: null to: 6.5 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Noam Moshe of Claroty Research - Team82
.