PT-2021-20557 · Unknown · Mbconnect24
Published
2021-08-02
·
Updated
2021-08-10
·
CVE-2021-34575
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
mbCONNECT24 versions <= 2.8.0
Description:
The issue allows an unauthenticated user to enumerate valid users by analyzing the server's response. This can be done by checking the kind of response the server sends, potentially revealing sensitive information about the system's users.
Recommendations:
For versions <= 2.8.0, update to a version greater than 2.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the server to minimize the risk of user enumeration.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mbconnect24