PT-2024-37781 · Tnb Mobile Solutions · Tnb Mobile Solutions Cockpit

Published

2024-09-13

·

Updated

2024-09-19

·

CVE-2024-6656

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TNB Mobile Solutions Cockpit Software versions prior to v2.13
Description The issue is related to the use of hard-coded credentials in TNB Mobile Solutions Cockpit Software, allowing unauthorized access to read sensitive strings within an executable.
Recommendations For versions prior to v2.13, update to version v2.13 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the software to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-6656

Affected Products

Tnb Mobile Solutions Cockpit