CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
Fixes

Solution

Update to MOTP 3.11.3 Patch 1 or later version or install the patch.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T19:32:42.703Z

Reserved: 2024-04-01T02:01:30.133Z

Link: CVE-2024-3122

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.703Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-01T05:15:04.693

Modified: 2024-11-21T09:28:56.983

Link: CVE-2024-3122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.