cvelist/2024/12xxx/CVE-2024-12057.json

122 lines
5.4 KiB
JSON
Raw Normal View History

2024-12-02 20:00:39 +00:00
{
2024-12-09 20:00:57 +00:00
"data_version": "4.0",
2024-12-02 20:00:39 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-12057",
2024-12-09 20:00:57 +00:00
"ASSIGNER": "secure@arcinfo.com",
"STATE": "PUBLIC"
2024-12-02 20:00:39 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2024-12-09 20:00:57 +00:00
"value": "User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.\nBy exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-532 Insertion of Sensitive Information into Log File",
"cweId": "CWE-532"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "arcinfo",
"product": {
"product_data": [
{
"product_name": "PcVue",
"version": {
"version_data": [
{
"version_affected": "<",
"version_name": "15.0",
"version_value": "16.2.4"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://www.pcvue.com/security/#SB2024-6",
"refsource": "MISC",
"name": "https://www.pcvue.com/security/#SB2024-6"
2024-12-02 20:00:39 +00:00
}
]
2024-12-09 20:00:57 +00:00
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"advisory": "SB2024-6",
"discovery": "EXTERNAL"
},
"configuration": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Only servers where the Web &amp; Mobile features are deployed are affected.<br>The PcVue Web back end and the Web Server must run different versions."
}
],
"value": "Only servers where the Web & Mobile features are deployed are affected.\nThe PcVue Web back end and the Web Server must run different versions."
}
],
"exploit": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "No POC available."
}
],
"value": "No POC available."
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Not known to be exploited"
}
],
"value": "Not known to be exploited"
}
],
"solution": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<b><u>Uninstall the Web Server<br></u></b>If your system does not require the use of the Web &amp; Mobile features, you should make sure not to install them. <br><b><u><br>Re-deploy the Web Server:</u></b><br>Re-deploy the Web Server with the Web Deployment Console (WDC) provided with the PcVue Web back end installation so that the PcVue Web back end and the Web server run the same version.<br><br>\n\n<b><u>Update the PcVue Web back end</u></b><br>Install a patched release of the product, including the Web back end and Web Deployment Console (WDC) and use the WDC to re-deploy the Web Server. In case of future updates, credentials will no longer be inserted into the Log files even if the PcVue back end and the Web server are incompatible.<br><br><b><u>Available patches:</u></b><br>Fixed in:<br><ul><li>16.2.4</li></ul>Planned in:<br><ul><li>15.2.11</li></ul>"
}
],
"value": "Uninstall the Web Server\nIf your system does not require the use of the Web & Mobile features, you should make sure not to install them. \n\nRe-deploy the Web Server:\nRe-deploy the Web Server with the Web Deployment Console (WDC) provided with the PcVue Web back end installation so that the PcVue Web back end and the Web server run the same version.\n\n\n\nUpdate the PcVue Web back end\nInstall a patched release of the product, including the Web back end and Web Deployment Console (WDC) and use the WDC to re-deploy the Web Server. In case of future updates, credentials will no longer be inserted into the Log files even if the PcVue back end and the Web server are incompatible.\n\nAvailable patches:\nFixed in:\n * 16.2.4\n\n\nPlanned in:\n * 15.2.11"
}
]
2024-12-02 20:00:39 +00:00
}