Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.
Fixes

Solution

The vulnerabilities have been resolved in versions 4.7 and later.


Workaround

No workaround given by the vendor.

History

Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Badgermeter
Badgermeter monitool
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:badgermeter:monitool:*:*:*:*:*:*:*:*
Vendors & Products Badgermeter
Badgermeter monitool

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-12T14:51:12.959Z

Reserved: 2024-02-07T10:22:54.601Z

Link: CVE-2024-1302

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.395Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-12T16:15:07.397

Modified: 2025-02-26T15:15:08.143

Link: CVE-2024-1302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.