A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-02T21:23:28.000Z

Updated: 2024-08-03T10:07:34.525Z

Reserved: 2022-07-25T00:00:00.000Z

Link: CVE-2022-36642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-02T22:15:08.477

Modified: 2024-11-21T07:13:27.210

Link: CVE-2022-36642

cve-icon Redhat

No data.