PT-2021-2244 · Mb Connect Line+1 · Mbconnect24+2
Published
2021-03-02
·
Updated
2023-02-10
·
CVE-2020-12527
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MB connect line mymbCONNECT24 versions through v2.11.2
mbCONNECT24 versions through v2.11.2
Helmholz myREX24 versions through v2.11.2
Helmholz myREX24.virtual versions through v2.11.2
Description
The issue is related to improper access validation, allowing a logged-in user to interact with devices in their account without having the corresponding permissions. This can lead to unauthorized shutdown or reboot of devices. The vulnerability may also allow a remote attacker to disclose protected information or cause a denial of service.
Recommendations
For MB connect line mymbCONNECT24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue.
For mbCONNECT24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue.
For Helmholz myREX24 versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue.
For Helmholz myREX24.virtual versions through v2.11.2, update to a version later than v2.11.2 to resolve the issue.
As a temporary workaround, consider restricting access to devices in the account to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mbconnect24
Myrex24
Myrex24.Virtual