A vulnerability has been identified in OPUPI0 AMQP/MQTT ...
Moderate severity
Unreviewed
Published
May 14, 2024
to the GitHub Advisory Database
•
Updated Aug 3, 2024
Description
Published by the National Vulnerability Database
May 14, 2024
Published to the GitHub Advisory Database
May 14, 2024
Last updated
Aug 3, 2024
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.
References