PT-2024-3750 · Unknown · Opupi0 Amqp/Mqtt
Constantin Schieber-Knoebl
+3
·
Published
2024-05-14
·
Updated
2024-07-09
·
CVE-2024-31486
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OPUPI0 AMQP/MQTT versions prior to V5.30
Description:
A vulnerability has been identified that allows an attacker with remote shell access or physical access to retrieve credentials due to insufficient protection of stored MQTT client passwords, leading to confidentiality loss. The issue is related to the storage of confidential information without encryption.
Recommendations:
For versions prior to V5.30, update to version V5.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opupi0 Amqp/Mqtt