CVE-2024-45273
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Affected (15)
Products: Mbconnectline: Mbnet.mini Firmware, Mbconnect24, Mymbconnect24, Mbspider Mdh 905 Firmware, Mbspider Mdh 915 Firmware, Mbspider Mdh 906 Firmware, Mbspider Mdh 916 Firmware, Mbnet Hw1 Firmware, Mbnet Firmware, Mbnet.rokey Firmware · Helmholz: Myrex24 V2 Virtual Server, Rex 300 Firmware, Rex 200 Firmware, Rex 250 Firmware, Rex 100 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.1 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbnet.mini | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.1.11 |
| Running on/with | Platform Versions |
|---|---|
Helmholz Rex 300 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.1 |
| Running on/with | Platform Versions |
|---|---|
Helmholz Rex 200 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.1 |
| Running on/with | Platform Versions |
|---|---|
Helmholz Rex 250 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.1 |
| Running on/with | Platform Versions |
|---|---|
Helmholz Rex 100 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.3 | |
| Before 2.16.3 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.5 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbspider Mdh 905 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.5 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbspider Mdh 915 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.5 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbspider Mdh 906 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.6.5 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbspider Mdh 916 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.1.11 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbnet Hw1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.1 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbnet | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.2.1 |
| Running on/with | Platform Versions |
|---|---|
Mbconnectline Mbnet.rokey | All versions |
Related CWEs
CWE-261
Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (5)
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.