MEDIUM
Sensitive Information Exposure in products of MB connect line and Helmholz
Published Feb 16, 2021
4.3
MEDIUMCVSS 3.1
EPSS 0.97%
Description
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.
Affected products
No data.
Configuration 1
OR
- ≤ 2.11.2
- ≤ 2.11.2
Configuration 2
OR
- ≤ 2.11.2
- ≤ 2.11.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 2.12.1
Weaknesses (1)
References (4)
- https://cert.vde.com/en/advisories/VDE-2021-003 x_refsource_CONFIRMThird Party Advisory
- https://cert.vde.com/en/advisories/VDE-2022-039 x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23235 Advisory
- https://mbconnectline.com/security-advice/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2021-003 | x_refsource_CONFIRMThird Party Advisory | |
| https://cert.vde.com/en/advisories/VDE-2022-039 | x_refsource_CONFIRMThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23235 | Advisory | |
| https://mbconnectline.com/security-advice/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2021
Updated Sep 17, 2024
Reserved Dec 18, 2020
Link CVE-2020-35568
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-23235 Assigner mitre
Published Feb 16, 2021
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2020-23235