Vulnerabilities > Mbconnectline > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-15 | CVE-2024-45271 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | 7.8 |
2024-10-15 | CVE-2024-45272 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost. | 7.5 |
2024-10-15 | CVE-2024-45273 | Inadequate Encryption Strength vulnerability in multiple products An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | 7.8 |
2024-10-15 | CVE-2024-45276 | Missing Authentication for Critical Function vulnerability in multiple products An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | 7.5 |
2023-06-06 | CVE-2023-0985 | Authorization Bypass Through User-Controlled Key vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24 An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. | 8.8 |
2021-08-02 | CVE-2021-33526 | Improper Privilege Management vulnerability in Mbconnectline Mbdialup In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service. | 7.2 |
2021-02-16 | CVE-2020-35558 | Server-Side Request Forgery (SSRF) vulnerability in multiple products An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. | 7.5 |
2020-04-14 | CVE-2020-10384 | Improper Privilege Management vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24 An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. | 7.2 |
2020-04-14 | CVE-2020-10382 | Unspecified vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24 An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. | 8.8 |