Description
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
Published: 2024-07-01
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to MOTP 3.11.3 Patch 1 or later version or install the patch.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-31723 CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T19:32:42.703Z

Reserved: 2024-04-01T02:01:30.133Z

Link: CVE-2024-3122

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.703Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-01T05:15:04.693

Modified: 2024-11-21T09:28:56.983

Link: CVE-2024-3122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses