CVE-2024-6785
6.8
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: psirt@moxa.com (Secondary)
Description
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
Affected (2)
Products: Moxa: Mxview One, Mxview One Central Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.1 | |
| Version 1.0.0 |
Related CWEs
References (2)
Source: psirt@moxa.com
Third Party AdvisoryUS Government Resource
Source: psirt@moxa.com
PatchVendor Advisory
Timeline
No history available yet.