CVE-2024-12057: User credentials recorded in log files

1.8 CVSS

Description

User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.

Classification

CVE ID: CVE-2024-12057

CVSS Base Severity: LOW

CVSS Base Score: 1.8

Affected Products

Vendor: arcinfo

Product: PcVue

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.pcvue.com/security/#SB2024-6

Timeline