CVE-2024-6785

Severity
6.8MEDIUM
EPSS
0.1%
top 77.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21

Description

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8hgr-rp5m-j4mg: The configuration file stores credentials in cleartext2024-09-21
CVEList
MXview One and MXview One Central Manager Series store cleartext credentials in a local file2024-09-21
CVE-2024-6785 (MEDIUM CVSS 6.8) | The configuration file stores crede | cvebase.io