CVE-2024-6785: MXview One and MXview One Central Manager Series store cleartext credentials in a local file
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6785?
CVE-2024-6785 is considered a high severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2024-6785?
To fix CVE-2024-6785, ensure that the configuration file does not store sensitive credentials in cleartext and implement proper encryption methods.
What types of systems are affected by CVE-2024-6785?
CVE-2024-6785 affects Moxa MXView One and MXView One Central Manager software, particularly versions up to 1.4.1 and exactly 1.0.0 respectively.
What potential risks are associated with CVE-2024-6785?
The risks associated with CVE-2024-6785 include unauthorized local access, modification of configuration files, and abuse of services leading to exposure of sensitive information.
Who can exploit CVE-2024-6785?
An attacker with local access rights can exploit CVE-2024-6785 to read or modify the vulnerable configuration files.