Impact
An unauthenticated attacker can exploit a SQL Injection in the dashboard view through improperly neutralized special elements in a SQL SELECT command, allowing arbitrary SQL code to be executed. This flaw is categorized as CWE-89 and can lead to a total loss of confidentiality by revealing sensitive data contained in the database.
Affected Systems
The vulnerability affects Helmholz products myREX24V2 and its virtual edition, as well as MB Connect Line products mbCONNECT24 and mymbCONNECT24. All affected releases are at version 2.20.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score is not available, suggesting limited publicly reported exploitation data. The vulnerability is not listed in the CISA KEV catalog, but its unauthenticated nature and SQL injection payload imply that an attacker could target the web-based dashboard endpoint directly to exfiltrate data. The primary attack vector is a crafted request sent to the dashboard view endpoint, which does not require privileged credentials.
OpenCVE Enrichment