An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-4829 An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.
Fixes

Solution

Update to v2.12.1


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T20:43:07.472Z

Reserved: 2020-04-30T00:00:00

Link: CVE-2020-12527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-02T22:15:12.387

Modified: 2024-11-21T04:59:52.400

Link: CVE-2020-12527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.