PT-2021-2244 · Mb Connect Line+1 · Mbconnect24+2

Published

2021-03-02

·

Updated

2023-02-10

·

CVE-2020-12527

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions MB connect line mymbCONNECT24 versions through v2.11.2 mbCONNECT24 versions through v2.11.2 Helmholz myREX24 versions through v2.11.2 Helmholz myREX24.virtual versions through v2.11.2
Description The issue is related to improper access validation, allowing a logged-in user to interact with devices in their account without having the corresponding permissions. This can lead to unauthorized shutdown or reboot of devices. The vulnerability may also allow a remote attacker to disclose protected information or cause a denial of service.
Recommendations For MB connect line mymbCONNECT24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue. For mbCONNECT24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue. For Helmholz myREX24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue. For Helmholz myREX24.virtual versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue. As a temporary workaround, consider restricting access to devices in the account to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-01215
CVE-2020-12527

Affected Products

Mbconnect24
Myrex24
Myrex24.Virtual