Vulnerabilities > Mbconnectline > Mymbconnect24

DATE CVE VULNERABILITY TITLE RISK
2024-10-15 CVE-2024-45273 Inadequate Encryption Strength vulnerability in multiple products
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
local
low complexity
mbconnectline helmholz CWE-326
7.8
2021-10-27 CVE-2021-34580 Information Exposure Through Discrepancy vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
network
low complexity
mbconnectline CWE-203
7.5
2021-08-02 CVE-2021-34575 Information Exposure Through Discrepancy vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.
network
low complexity
mbconnectline CWE-203
7.5
2021-03-02 CVE-2020-12530 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2.
network
low complexity
mbconnectline CWE-79
6.1
2021-03-02 CVE-2020-12529 Server-Side Request Forgery (SSRF) vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
network
low complexity
mbconnectline CWE-918
5.3
2021-03-02 CVE-2020-12528 Improper Privilege Management vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2.
network
low complexity
mbconnectline CWE-269
7.7
2021-02-16 CVE-2020-35570 Forced Browsing vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2.
network
low complexity
mbconnectline helmholz CWE-425
5.3
2021-02-16 CVE-2020-35569 Cross-site Scripting vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-79
6.1
2021-02-16 CVE-2020-35568 Information Exposure vulnerability in multiple products
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
network
low complexity
mbconnectline helmholz CWE-200
4.3
2021-02-16 CVE-2020-35567 Use of Hard-coded Credentials vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
local
low complexity
mbconnectline CWE-798
7.8