CVE-2024-6785

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mxview_one_central_manager:1.0.0:*:*:*:*:*:*:*

History

27 Sep 2024, 18:59

Type Values Removed Values Added
First Time Moxa mxview One Central Manager
Moxa
Moxa mxview One
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mxview_one_central_manager:1.0.0:*:*:*:*:*:*:*
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - Patch, Vendor Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - Third Party Advisory, US Government Resource

26 Sep 2024, 07:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 -

21 Sep 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-21 05:15

Updated : 2024-09-27 18:59


NVD link : CVE-2024-6785

Mitre link : CVE-2024-6785


JSON object : View

Products Affected

moxa

  • mxview_one_central_manager
  • mxview_one
CWE
CWE-312

Cleartext Storage of Sensitive Information