CVE-2024-6786
CVE-2024-6786
Título es
CVE-2024-6786
Sáb, 21/09/2024 – 05:15
Tipo
CWE-24
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-6786
Descripción en
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
21/09/2024
21/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
6.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Enviar en el boletín
Off