5.3

CVE-2020-35570

Foreced Browsing vulnerability in products of MB connect line and Helmholz

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbconnectline ≫ Mbconnect24 Version <= 2.11.2
Mbconnectline ≫ Mymbconnect24 Version <= 2.11.2
Helmholz ≫ Myrex24 Version <= 2.11.2
Helmholz ≫ Myrex24.Virtual Version <= 2.11.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.655
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
MITRE 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://mbconnectline.com/security-advice/
Vendor Advisory
https://cert.vde.com/en/advisories/VDE-2021-003
Third Party Advisory
https://cert.vde.com/en/advisories/VDE-2022-039
Third Party Advisory