Unprotected storage of credentials in MDLC - CVE-2022-30275
Published: June 29, 2022
MDLC
Motorola
Description
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to the affected product utilizes an MDLC driver that has a password stored in plaintext in the wmdlcdrv.ini driver configuration file. A remote attacker can view contents of the configuration file and gain access to passwords for 3rd party integration.