Assigner | siemens |
Reserved | 2024-04-04 |
Published | 2024-05-14 |
Updated | 2024-07-23 |
Description
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N | |
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Problem types
CWE-312: Cleartext Storage of Sensitive Information
Product status
Any version before V5.30
References
https://cert-portal.siemens.com/productcert/html/ssa-871704.html
http://seclists.org/fulldisclosure/2024/Jul/4