The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 | Third Party Advisory US Government Resource |
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
27 Sep 2024, 18:59
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-312 | |
CPE | cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:* cpe:2.3:a:moxa:mxview_one_central_manager:1.0.0:*:*:*:*:*:*:* |
|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - Third Party Advisory, US Government Resource | |
References | () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
First Time |
Moxa mxview One Central Manager
Moxa mxview One Moxa |
26 Sep 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
21 Sep 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-21 05:15
Updated : 2024-09-27 18:59
NVD link : CVE-2024-6785
Mitre link : CVE-2024-6785
CVE.ORG link : CVE-2024-6785
JSON object : View
Products Affected
moxa
- mxview_one_central_manager
- mxview_one