PT-2024-3750 · Unknown · Opupi0 Amqp/Mqtt

Constantin Schieber-Knoebl

+3

·

Published

2024-05-14

·

Updated

2024-07-09

·

CVE-2024-31486

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OPUPI0 AMQP/MQTT versions prior to V5.30
Description: A vulnerability has been identified that allows an attacker with remote shell access or physical access to retrieve credentials due to insufficient protection of stored MQTT client passwords, leading to confidentiality loss. The issue is related to the storage of confidential information without encryption.
Recommendations: For versions prior to V5.30, update to version V5.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-04096
CVE-2024-31486

Affected Products

Opupi0 Amqp/Mqtt