By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50562 | User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application. |
Solution
Uninstall the Web Server If your system does not require the use of the Web & Mobile features, you should make sure not to install them. Re-deploy the Web Server: Re-deploy the Web Server with the Web Deployment Console (WDC) provided with the PcVue Web back end installation so that the PcVue Web back end and the Web server run the same version. Update the PcVue Web back end Install a patched release of the product, including the Web back end and Web Deployment Console (WDC) and use the WDC to re-deploy the Web Server. In case of future updates, credentials will no longer be inserted into the Log files even if the PcVue back end and the Web server are incompatible. Available patches: Fixed in: * 16.2.4 * 15.2.11
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.pcvue.com/security/#SB2024-6 |
|
Tue, 10 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application. | |
| Title | User credentials recorded in log files | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: arcinfo
Published:
Updated: 2025-03-21T15:55:47.995Z
Reserved: 2024-12-02T19:57:23.640Z
Link: CVE-2024-12057
Updated: 2024-12-10T21:22:46.259Z
Status : Received
Published: 2024-12-09T19:15:12.750
Modified: 2024-12-09T19:15:12.750
Link: CVE-2024-12057
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:59Z
EUVD