PT-2024-37781 · Tnb Mobile Solutions · Tnb Mobile Solutions Cockpit

CVE-2024-6656

·

Published

2024-09-13

·

Updated

2024-09-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TNB Mobile Solutions Cockpit Software versions prior to v2.13
Description The issue is related to the use of hard-coded credentials in TNB Mobile Solutions Cockpit Software, allowing unauthorized access to read sensitive strings within an executable.
Recommendations For versions prior to v2.13, update to version v2.13 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the software to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6656

Affected Products

Tnb Mobile Solutions Cockpit