CVE-2020-12527

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:helmholz:myrex24:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*

History

10 Feb 2023, 18:03

Type Values Removed Values Added
CPE cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24:*:*:*:*:*:*:*:*
References (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-003 - (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-003 - Third Party Advisory
References (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 - (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 - Third Party Advisory
CVSS v2 : 4.0
v3 : 6.5
v2 : 6.8
v3 : 6.5
First Time Helmholz
Helmholz myrex24
Helmholz myrex24.virtual

16 Sep 2022, 06:15

Type Values Removed Values Added
Summary An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices belonging to another user account. An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.

14 Sep 2022, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://cert.vde.com/de-de/advisories/vde-2021-003', 'name': 'https://cert.vde.com/de-de/advisories/vde-2021-003', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 -
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-003 -
Summary An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to interact with devices in the account he should not have access to. An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices belonging to another user account.
CVSS v2 : 4.0
v3 : 4.3
v2 : 4.0
v3 : 6.5

09 Mar 2021, 16:08

Type Values Removed Values Added
CWE CWE-269
References (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-003 - (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-003 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CPE cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

02 Mar 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-02 22:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-12527

Mitre link : CVE-2020-12527

CVE.ORG link : CVE-2020-12527


JSON object : View

Products Affected

mbconnectline

  • mymbconnect24
  • mbconnect24

helmholz

  • myrex24.virtual
  • myrex24
CWE
CWE-269

Improper Privilege Management