cbcvebase.
CVE-2024-6785
published 2024-09-21

CVE-2024-6785: The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.11%
1.7th percentile
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

Affected

4 ranges
VendorProductVersion rangeFixed in
moxamxview_one< 1.4.11.4.1
moxamxview_one_central_manager
moxamxview_one_central_manager_series< 1.0.01.0.0
moxamxview_one_series< 1.3.01.3.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.