← back
CVE-2024-6786

MXview One Series vulnerable to Path Traversal

CVSS 6 MEDIUMEPSS 0.5%CWE-24
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.5%KEV nãoPoC Patch referenciado
Lifecycle
21 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Moxa · MXview One Series

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →