5.3
CVE-2026-33617
- EPSS 0.05%
- Veröffentlicht 02.04.2026 09:00:10
- Zuletzt bearbeitet 16.04.2026 15:40:56
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint
An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mbconnectline ≫ Mbconnect24 Version <= 2.19.4
Mbconnectline ≫ Mymbconnect24 Version <= 2.19.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.148 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.