CVE-2021-34574

In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:helmholz:myrex24:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*

History

14 Sep 2022, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://cert.vde.com/de-de/advisories/vde-2021-030', 'name': 'https://cert.vde.com/de-de/advisories/vde-2021-030', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-030 -
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 -
Summary In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server. In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

10 Aug 2021, 18:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-030 - (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-030 - Third Party Advisory
CWE CWE-669
CPE cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*

02 Aug 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-02 11:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-34574

Mitre link : CVE-2021-34574

CVE.ORG link : CVE-2021-34574


JSON object : View

Products Affected

mbconnectline

  • mbconnect24
  • mymbconnect24

helmholz

  • myrex24.virtual
  • myrex24
CWE
CWE-669

Incorrect Resource Transfer Between Spheres