01642 06 11 11 Arrange Call

Insecure Storage of MQTT Client Passwords in OPUPI0 AMQP/MQTT (All versions < V5.30)

CVE-2024-31486 · MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2024-31486

A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.

Learn more about our Physical Security Assessment.