Description
In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
No analysis available yet.
Remediation
Vendor Solution
Update to version 2.12.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21224 | In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server. |
References
History
No history.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-16T18:14:15.495Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34574
No data.
Status : Modified
Published: 2021-08-02T11:15:11.350
Modified: 2024-11-21T06:10:43.910
Link: CVE-2021-34574
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD