CVE-2024-6785

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mxview_one_central_manager:1.0.0:*:*:*:*:*:*:*

History

27 Sep 2024, 18:59

Type Values Removed Values Added
CWE CWE-312
CPE cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:mxview_one_central_manager:1.0.0:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - Third Party Advisory, US Government Resource
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.1
First Time Moxa mxview One Central Manager
Moxa mxview One
Moxa

26 Sep 2024, 07:15

Type Values Removed Values Added
Summary
  • (es) El archivo de configuración almacena las credenciales en texto plano. Un atacante con derechos de acceso local puede leer o modificar el archivo de configuración, lo que podría provocar un uso indebido del servicio debido a la exposición de información confidencial.
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 -

21 Sep 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-21 05:15

Updated : 2024-09-27 18:59


NVD link : CVE-2024-6785

Mitre link : CVE-2024-6785

CVE.ORG link : CVE-2024-6785


JSON object : View

Products Affected

moxa

  • mxview_one_central_manager
  • mxview_one
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-313

Cleartext Storage in a File or on Disk