PT-2024-19548 · Amcs · Trux Waste Management

Bryan Smith

+1

·

Published

2024-04-09

·

Updated

2025-06-17

·

CVE-2024-22734

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AMCS Group Trux Waste Management Software versions prior to 7.19.0018.26912
Description An issue in the Trux Waste Management Software allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components. This could allow attackers with local network access to take complete control of the application and gain unrestricted access to sensitive ERP databases.
Recommendations For versions prior to 7.19.0018.26912, update to version 7.19.0018.26912 or later to resolve the issue. As a temporary workaround, consider restricting access to the TxUtilities.dll and TruxUser.cfg components to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-22734

Affected Products

Trux Waste Management