Impact
The vulnerability allows any authenticated user, even with low privileges, to obtain the OPC‑UA authentication credentials in clear text from the JSON response of the opcua-configuration method in /cgi-bin/wwwugw.cgi. The disclosure of these credentials compromises confidentiality of the authentication mechanism. Based on the description, it is inferred that an attacker could use the exposed credentials to access the OPC‑UA service and potentially perform unauthorized operations. However, the CVE description does not explicitly state the extent of impact beyond credential disclosure.
Affected Systems
The flaw exists in the firmware of MBS‑Solutions X‑Serie Gateway, version V6_00_05. No other firmware versions were explicitly mentioned in the advisories.
Risk and Exploitability
Because the attack requires only remote authentication and can be carried out by low‑privileged users, the risk to operators who depend on OPC‑UA is significant. The EPSS score of 0.292% (0.00292) indicates that the likelihood of exploitation is low, and the vulnerability is not listed in the KEV catalog, but the exposure of credentials is a high‑impact security issue that could be exploited in environments with an active OPC‑UA service. Additionally, the CVSS score of 6.5 categorizes this vulnerability as medium severity.
OpenCVE Enrichment