User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50562 User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
Fixes

Solution

Uninstall the Web Server If your system does not require the use of the Web & Mobile features, you should make sure not to install them. Re-deploy the Web Server: Re-deploy the Web Server with the Web Deployment Console (WDC) provided with the PcVue Web back end installation so that the PcVue Web back end and the Web server run the same version. Update the PcVue Web back end Install a patched release of the product, including the Web back end and Web Deployment Console (WDC) and use the WDC to re-deploy the Web Server. In case of future updates, credentials will no longer be inserted into the Log files even if the PcVue back end and the Web server are incompatible. Available patches: Fixed in: * 16.2.4 * 15.2.11


Workaround

No workaround given by the vendor.

References
History

Tue, 10 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Description User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
Title User credentials recorded in log files
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N/R:U/V:C/RE:M/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: arcinfo

Published:

Updated: 2025-03-21T15:55:47.995Z

Reserved: 2024-12-02T19:57:23.640Z

Link: CVE-2024-12057

cve-icon Vulnrichment

Updated: 2024-12-10T21:22:46.259Z

cve-icon NVD

Status : Received

Published: 2024-12-09T19:15:12.750

Modified: 2024-12-09T19:15:12.750

Link: CVE-2024-12057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:31:59Z