PT-2024-7786 · Unknown · Mxview One+1

Noam Moshe

·

Published

2024-07-16

·

Updated

2024-09-27

·

CVE-2024-6785

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MXview One and MXview One Central Manager (affected versions not specified)
Description The configuration file stores credentials in cleartext, allowing an attacker with local access rights to read or modify the file. This could result in the service being abused due to sensitive information exposure, potentially leading to unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-09286
CVE-2024-6785

Affected Products

Mxview One
Mxview One Central Manager