Vulnerabilities (CVE)

Filtered by vendor Helmholz Subscribe
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45271 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2024-10-21 N/A 7.8 HIGH
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
CVE-2024-45272 2 Helmholz, Mbconnectline 23 Myrex24 V2 Virtual Server, Rex 200, Rex 200 Firmware and 20 more 2024-10-17 N/A 7.5 HIGH
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
CVE-2024-45273 2 Helmholz, Mbconnectline 27 Myrex24 V2 Virtual Server, Rex 100, Rex 100 Firmware and 24 more 2024-10-17 N/A 7.8 HIGH
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
CVE-2024-45274 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2024-10-17 N/A 9.8 CRITICAL
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-45275 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2024-10-17 N/A 9.8 CRITICAL
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
CVE-2024-45276 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2024-10-17 N/A 7.5 HIGH
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2022-22520 2 Helmholz, Mbconnectline 4 Myrex24, Myrex24.virtual, Mbconnect24 and 1 more 2024-02-04 N/A 5.3 MEDIUM
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.