CVE-2024-6786

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*

History

30 Sep 2024, 18:31

Type Values Removed Values Added
First Time Moxa
Moxa mxview One
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 - Third Party Advisory, US Government Resource
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240735-multiple-vulnerabilities-in-mxview-one-and-mxview-one-central-manager-series - Patch, Vendor Advisory
CWE CWE-22
CPE cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad permite a un atacante manipular mensajes MQTT que incluyen secuencias de relative path traversal, lo que les permite leer archivos arbitrarios en el sistema. Esto podría llevar a la divulgación de información confidencial, como archivos de configuración y secretos de firma JWT.
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05 -

21 Sep 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-21 05:15

Updated : 2024-09-30 18:31


NVD link : CVE-2024-6786

Mitre link : CVE-2024-6786

CVE.ORG link : CVE-2024-6786


JSON object : View

Products Affected

moxa

  • mxview_one
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-24

Path Traversal: '../filedir'