CVE-2024-6786

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:moxa:mxview_one:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-21 05:15

Updated : 2024-09-30 18:31


NVD link : CVE-2024-6786

Mitre link : CVE-2024-6786

CVE.ORG link : CVE-2024-6786


JSON object : View

Products Affected

moxa

  • mxview_one
CWE
CWE-24

Path Traversal: '../filedir'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')