Vulnerabilites related to helmholz - rex_100_firmware
Vulnerability from fkie_nvd
Published
2024-10-15 11:15
Modified
2024-11-21 09:37
Severity ?
8.4 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
References
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E4E80D53-0907-45AF-A03B-A093C5CEA33B", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*", "matchCriteriaId": "A1D1B769-DA91-4F0C-AD34-D735B7A8B8FF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:helmholz:myrex24_v2_virtual_server:*:*:*:*:*:*:*:*", "matchCriteriaId": "5D5B73E2-38BA-415D-96AF-D0F835E3C9BC", "versionEndExcluding": "2.16.3", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_300_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "05CB17C2-1B86-41AA-8737-718BA9464BB0", "versionEndIncluding": "5.1.11", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_300:-:*:*:*:*:*:*:*", "matchCriteriaId": "DB65F958-3FF4-48A7-8007-406A7FDBA0E7", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_200_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE10F9E9-A0EE-4CF1-9F4B-6AF4179ED03E", "versionEndExcluding": "8.2.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:*", "matchCriteriaId": "28B3785D-8EFF-4A67-88F1-8F9D0EC39D6C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_250_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "67ECB608-F99D-479C-95CC-349DCB530D98", "versionEndExcluding": "8.2.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_250:-:*:*:*:*:*:*:*", "matchCriteriaId": "53454815-3E7A-4097-8FC7-2F7634DAF7E1", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "F226166A-1261-43F9-81EC-E1C0FC9CB6E6", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "E7E8BE39-3C4A-484A-A34D-3CB4B46E41FA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F017673-3A54-4D92-811F-AE395CCED7CF", "versionEndExcluding": "2.16.3", "vulnerable": true }, { "criteria": "cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*", "matchCriteriaId": "18BC8E52-E277-4D72-903A-A31FC658B6E2", "versionEndExcluding": "2.16.3", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbspider_mdh_905_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "188A4550-AE25-459E-9624-97090842230B", "versionEndIncluding": "2.6.5", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbspider_mdh_905:-:*:*:*:*:*:*:*", "matchCriteriaId": "5ABBF6FE-BF26-43B2-B54C-6ECE4234B3C9", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbspider_mdh_915_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "3CAEA6C5-27F5-4BA5-BEB4-DD2EDE66F877", "versionEndIncluding": "2.6.5", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbspider_mdh_915:-:*:*:*:*:*:*:*", "matchCriteriaId": "ED665544-6D67-465A-8850-6FD7A44D9E6F", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbspider_mdh_906_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E41557B9-9BE2-4286-A1FE-88CDAD14B824", "versionEndIncluding": "2.6.5", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbspider_mdh_906:-:*:*:*:*:*:*:*", "matchCriteriaId": "63B499C3-0C59-488D-89E7-2CBEEA42E1E9", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbspider_mdh_916_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "75321482-BFC4-4D37-AF03-9212AE6028A7", "versionEndIncluding": "2.6.5", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbspider_mdh_916:-:*:*:*:*:*:*:*", "matchCriteriaId": "B74973FF-4DC9-4076-A161-28EC0A5F5E6D", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet_hw1_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "7470E3A2-72C5-4743-ABC2-14FB4C9F02D8", "versionEndIncluding": "5.1.11", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet_hw1:-:*:*:*:*:*:*:*", "matchCriteriaId": "83E49632-8868-4BF8-A86D-E7F10130B378", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "40166B67-481E-4B36-BBD8-4F5721B75B9E", "versionEndExcluding": "8.2.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet:-:*:*:*:*:*:*:*", "matchCriteriaId": "4D8CB051-1E1A-4014-9FB2-4473AC4CEE30", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.rokey_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "2AE59454-A9F9-44BE-8B06-9A631332A4E9", "versionEndExcluding": "8.2.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.rokey:-:*:*:*:*:*:*:*", "matchCriteriaId": "CC7B6E4C-1AC2-4CD8-A056-2EF8845622CA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used." }, { "lang": "es", "value": "Un atacante local no autenticado puede descifrar el archivo de configuraci\u00f3n del dispositivo y, por lo tanto, comprometer el dispositivo debido a una implementaci\u00f3n d\u00e9bil del cifrado utilizado." } ], "id": "CVE-2024-45273", "lastModified": "2024-11-21T09:37:35.450", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 8.4, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.5, "impactScore": 5.9, "source": "info@cert.vde.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-10-15T11:15:11.940", "references": [ { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-068" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-069" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-062.txt" } ], "sourceIdentifier": "info@cert.vde.com", "vulnStatus": "Undergoing Analysis", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-261" } ], "source": "info@cert.vde.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-326" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-10-15 11:15
Modified
2024-11-21 09:37
Severity ?
9.8 (Critical) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (Critical) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 (Critical) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
mbconnectline | mbnet.mini_firmware | * | |
mbconnectline | mbnet.mini | - | |
helmholz | rex_100_firmware | * | |
helmholz | rex_100 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E4E80D53-0907-45AF-A03B-A093C5CEA33B", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*", "matchCriteriaId": "A1D1B769-DA91-4F0C-AD34-D735B7A8B8FF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "F226166A-1261-43F9-81EC-E1C0FC9CB6E6", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "E7E8BE39-3C4A-484A-A34D-3CB4B46E41FA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices." }, { "lang": "es", "value": "Los dispositivos contienen dos cuentas de usuario codificadas con contrase\u00f1as codificadas que permiten a un atacante remoto no autenticado tener control total de los dispositivos afectados." } ], "id": "CVE-2024-45275", "lastModified": "2024-11-21T09:37:35.750", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "info@cert.vde.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-10-15T11:15:12.487", "references": [ { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-064.txt" } ], "sourceIdentifier": "info@cert.vde.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-798" } ], "source": "info@cert.vde.com", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-10-15 11:15
Modified
2024-11-21 09:37
Severity ?
Summary
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
mbconnectline | mbnet.mini_firmware | * | |
mbconnectline | mbnet.mini | - | |
helmholz | rex_100_firmware | * | |
helmholz | rex_100 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E4E80D53-0907-45AF-A03B-A093C5CEA33B", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*", "matchCriteriaId": "A1D1B769-DA91-4F0C-AD34-D735B7A8B8FF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "F226166A-1261-43F9-81EC-E1C0FC9CB6E6", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "E7E8BE39-3C4A-484A-A34D-3CB4B46E41FA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication." }, { "lang": "es", "value": "Un atacante remoto no autenticado puede ejecutar comandos del sistema operativo a trav\u00e9s de UDP en el dispositivo debido a la falta de autenticaci\u00f3n." } ], "id": "CVE-2024-45274", "lastModified": "2024-11-21T09:37:35.617", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "info@cert.vde.com", "type": "Primary" } ] }, "published": "2024-10-15T11:15:12.247", "references": [ { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-063.txt" } ], "sourceIdentifier": "info@cert.vde.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-306" } ], "source": "info@cert.vde.com", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-10-15 11:15
Modified
2025-08-22 07:15
Severity ?
8.4 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
mbconnectline | mbnet.mini_firmware | * | |
mbconnectline | mbnet.mini | - | |
helmholz | rex_100_firmware | * | |
helmholz | rex_100 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E4E80D53-0907-45AF-A03B-A093C5CEA33B", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*", "matchCriteriaId": "A1D1B769-DA91-4F0C-AD34-D735B7A8B8FF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "F226166A-1261-43F9-81EC-E1C0FC9CB6E6", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "E7E8BE39-3C4A-484A-A34D-3CB4B46E41FA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation." }, { "lang": "es", "value": "Un atacante local no autenticado puede obtener privilegios de administrador al implementar un archivo de configuraci\u00f3n debido a una validaci\u00f3n de entrada incorrecta." } ], "id": "CVE-2024-45271", "lastModified": "2025-08-22T07:15:44.713", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 8.4, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.5, "impactScore": 5.9, "source": "info@cert.vde.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-10-15T11:15:11.420", "references": [ { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-059.txt" } ], "sourceIdentifier": "info@cert.vde.com", "vulnStatus": "Undergoing Analysis", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-94" } ], "source": "info@cert.vde.com", "type": "Primary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-116" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-10-15 11:15
Modified
2025-01-24 07:15
Severity ?
Summary
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
mbconnectline | mbnet.mini_firmware | * | |
mbconnectline | mbnet.mini | - | |
helmholz | rex_100_firmware | * | |
helmholz | rex_100 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "E4E80D53-0907-45AF-A03B-A093C5CEA33B", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*", "matchCriteriaId": "A1D1B769-DA91-4F0C-AD34-D735B7A8B8FF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "F226166A-1261-43F9-81EC-E1C0FC9CB6E6", "versionEndExcluding": "2.3.1", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "E7E8BE39-3C4A-484A-A34D-3CB4B46E41FA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An unauthenticated remote attacker can get read access to files in the \"/tmp\" directory due to missing authentication." }, { "lang": "es", "value": "Un atacante remoto no autenticado puede obtener acceso de lectura a los archivos en el directorio \"/tmp\" debido a la falta de autenticaci\u00f3n." } ], "id": "CVE-2024-45276", "lastModified": "2025-01-24T07:15:10.320", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "info@cert.vde.com", "type": "Primary" } ] }, "published": "2024-10-15T11:15:12.760", "references": [ { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "source": "info@cert.vde.com", "tags": [ "Third Party Advisory" ], "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-065.txt" } ], "sourceIdentifier": "info@cert.vde.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-306" } ], "source": "info@cert.vde.com", "type": "Primary" }, { "description": [ { "lang": "en", "value": "CWE-306" } ], "source": "nvd@nist.gov", "type": "Secondary" } ] }
CVE-2024-45274 (GCVE-0-2024-45274)
Vulnerability from cvelistv5
Published
2024-10-15 10:28
Modified
2024-10-16 17:44
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-306 - Missing Authentication for Critical Function
Summary
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | MB connect line | mbNET.mini |
Version: 0.0.0 ≤ 2.2.13 |
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex_100_firmware", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex_100_firmware", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-45274", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-10-15T13:33:38.579567Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-10-15T13:34:58.690Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-10-16T17:44:15.429Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-063.txt" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "mbNET.mini", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX100", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Moritz Abrell" }, { "lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "SySS GmbH" } ], "datePublic": "2024-10-15T08:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.\u003cbr\u003e" } ], "value": "An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-306", "description": "CWE-306 Missing Authentication for Critical Function", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-10-15T10:28:16.384Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-066" } ], "source": { "advisory": "VDE-2024-056, VDE-2024-066", "defect": [ "CERT@VDE#641679", "CERT@VDE#641692" ], "discovery": "UNKNOWN" }, "title": "MB connect line/Helmholz: Remote code execution via confnet service", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2024-45274", "datePublished": "2024-10-15T10:28:16.384Z", "dateReserved": "2024-08-26T09:19:01.266Z", "dateUpdated": "2024-10-16T17:44:15.429Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-45273 (GCVE-0-2024-45273)
Vulnerability from cvelistv5
Published
2024-10-15 10:27
Modified
2024-10-16 17:47
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-261 - Weak Encoding for Password
Summary
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | MB connect line | mbNET.mini |
Version: 0.0.0 ≤ 2.2.13 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mbconnectline:mbnet_mbnet.rokey:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet_mbnet.rokey", "vendor": "mbconnectline", "versions": [ { "lessThanOrEqual": "8.2.0", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mbconnectline:mbnet_hw1:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet_hw1", "vendor": "mbconnectline", "versions": [ { "lessThanOrEqual": "5.1.11", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mbconnectline:mbspider:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbspider", "vendor": "mbconnectline", "versions": [ { "lessThanOrEqual": "2.6.5", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mbconnectline:mbconnect24:-:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbconnect24", "vendor": "mbconnectline", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:mbconnectline:mymbconnect24:-:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mymbconnect24", "vendor": "mbconnectline", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex100:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex100", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex_200", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "8.2.0", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex250:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex250", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "8.2.0", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:myrex24_v2:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "myrex24_v2", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "myrex24.virtual", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex300:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex300", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "5.1.11", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-45273", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-10-15T18:22:26.955543Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-10-15T18:31:20.013Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-10-16T17:47:04.737Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-062.txt" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "mbNET.mini", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "mbNET/mbNET.rokey", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "8.2.0", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "mbNET HW1", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "5.1.11", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "mbSPIDER", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.6.5", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "mbCONNECT24", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "mymbCONNECT24", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.16.2", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX100", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "\u003c= 2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX200/250", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "\u003c= 8.2.0", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "myREX24 V2", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "\u003c= 2.16.2", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "myREX24.virtual", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "\u003c= 2.16.2", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX300", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "\u003c= 5.1.11", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Moritz Abrell" }, { "lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "SySS GmbH" } ], "datePublic": "2024-10-15T08:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.\u003cbr\u003e" } ], "value": "An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 8.4, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-261", "description": "CWE-261: Weak Encoding for Password", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-10-15T10:27:52.208Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-066" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-068" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-069" } ], "source": { "advisory": "VDE-2024-056, VDE-2024-066, VDE-2024-068, VDE-2024-069", "defect": [ "CERT@VDE#641679", "CERT@VDE#641695", "CERT@VDE#641692", "CERT@VDE#641696" ], "discovery": "UNKNOWN" }, "title": "MB connect line/Helmholz: Weak encryption of configuration file", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2024-45273", "datePublished": "2024-10-15T10:27:52.208Z", "dateReserved": "2024-08-26T09:19:01.266Z", "dateUpdated": "2024-10-16T17:47:04.737Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-45271 (GCVE-0-2024-45271)
Vulnerability from cvelistv5
Published
2024-10-15 10:27
Modified
2025-08-22 06:55
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-94 - Improper Control of Generation of Code ('Code Injection')
Summary
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | MB connect line | mbNET.mini |
Version: 0.0.0 ≤ 2.2.13 |
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:rex100:helmholz:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "helmholz", "vendor": "rex100", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-45271", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-10-15T13:12:42.565246Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-116", "description": "CWE-116 Improper Encoding or Escaping of Output", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-10-15T13:16:25.778Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-10-16T17:49:30.446Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-059.txt" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "mbNET.mini", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX100", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Moritz Abrell" }, { "lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "SySS GmbH" } ], "datePublic": "2024-10-15T08:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.\u003cbr\u003e" } ], "value": "An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 8.4, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-94", "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-22T06:55:23.671Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-066" } ], "source": { "advisory": "VDE-2024-056, VDE-2024-066", "defect": [ "CERT@VDE#641679", "CERT@VDE#641692" ], "discovery": "UNKNOWN" }, "title": "MB connect line/Helmholz: Remote code execution due to improper input validation", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2024-45271", "datePublished": "2024-10-15T10:27:06.004Z", "dateReserved": "2024-08-26T09:19:01.266Z", "dateUpdated": "2025-08-22T06:55:23.671Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-45276 (GCVE-0-2024-45276)
Vulnerability from cvelistv5
Published
2024-10-15 10:28
Modified
2025-01-24 06:32
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-306 - Missing Authentication for Critical Function
Summary
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | MB connect line | mbNET.mini |
Version: 0.0.0 ≤ 2.2.13 |
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex_100_firmware", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-45276", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-10-15T13:28:49.058765Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-10-15T13:30:48.688Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-10-16T17:16:43.319Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-065.txt" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "mbNET.mini", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX100", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Moritz Abrell" }, { "lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "SySS GmbH" } ], "datePublic": "2024-10-15T08:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An unauthenticated remote attacker can get read access to files in the \"/tmp\" directory due to missing authentication.\u003cbr\u003e" } ], "value": "An unauthenticated remote attacker can get read access to files in the \"/tmp\" directory due to missing authentication." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-306", "description": "CWE-306 Missing Authentication for Critical Function", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-24T06:32:08.237Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-066" } ], "source": { "advisory": "VDE-2024-056, VDE-2024-066", "defect": [ "CERT@VDE#641679", "CERT@VDE#641692" ], "discovery": "UNKNOWN" }, "title": "MB connect line/Helmholz: tmp directory exposed via webservice", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2024-45276", "datePublished": "2024-10-15T10:28:58.559Z", "dateReserved": "2024-08-26T09:19:01.267Z", "dateUpdated": "2025-01-24T06:32:08.237Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-45275 (GCVE-0-2024-45275)
Vulnerability from cvelistv5
Published
2024-10-15 10:28
Modified
2024-10-16 17:39
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-798 - Use of Hard-coded Credentials
Summary
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | MB connect line | mbNET.mini |
Version: 0.0.0 ≤ 2.2.13 |
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:mb_connect_line:mbnet.mini:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "mbnet.mini", "vendor": "mb_connect_line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] }, { "cpes": [ "cpe:2.3:a:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "rex_100_firmware", "vendor": "helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0", "versionType": "semver" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-45275", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-10-15T13:31:57.475980Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-10-15T13:33:13.397Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-10-16T17:39:58.106Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-064.txt" } ], "title": "CVE Program Container", "x_generator": { "engine": "ADPogram 0.0.1" } } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "mbNET.mini", "vendor": "MB connect line", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "REX100", "vendor": "Helmholz", "versions": [ { "lessThanOrEqual": "2.2.13", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Moritz Abrell" }, { "lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "SySS GmbH" } ], "datePublic": "2024-10-15T08:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.\u003cbr\u003e" } ], "value": "The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-798", "description": "CWE-798 Use of Hard-coded Credentials", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-10-15T10:28:37.223Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://cert.vde.com/en/advisories/VDE-2024-056" }, { "url": "https://cert.vde.com/en/advisories/VDE-2024-066" } ], "source": { "advisory": "VDE-2024-056, VDE-2024-066", "defect": [ "CERT@VDE#641679", "CERT@VDE#641692" ], "discovery": "UNKNOWN" }, "title": "MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2024-45275", "datePublished": "2024-10-15T10:28:37.223Z", "dateReserved": "2024-08-26T09:19:01.266Z", "dateUpdated": "2024-10-16T17:39:58.106Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }