A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-02T21:23:28

Updated: 2024-08-03T10:07:34.525Z

Reserved: 2022-07-25T00:00:00

Link: CVE-2022-36642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-02T22:15:08.477

Modified: 2022-09-27T15:40:10.233

Link: CVE-2022-36642

cve-icon Redhat

No data.