CVE-2024-12057

EUVD-2024-50562
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
arcinfoCNA
1.8 LOW
LOCAL
HIGH
HIGH
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:N/R:U/V:C/RE:M/U:Clear
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
arcinfopcvue
16.0.0 ≤
𝑥
< 16.2.4
CNA
arcinfopcvue
15.0.0 ≤
𝑥
< 15.2.11
CNA