CVE-2021-34574

In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:helmholz:myrex24:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*

History

03 Feb 2023, 16:15

Type Values Removed Values Added
References (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 - (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 - Third Party Advisory
References (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-030 - (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-030 - Third Party Advisory
CPE cpe:2.3:a:helmholz:myrex24.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24:*:*:*:*:*:*:*:*
First Time Helmholz
Helmholz myrex24
Helmholz myrex24.virtual

14 Sep 2022, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://cert.vde.com/de-de/advisories/vde-2021-030', 'name': 'https://cert.vde.com/de-de/advisories/vde-2021-030', 'tags': ['Third Party Advisory'], 'refsource': 'CONFIRM'}
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2022-039 -
  • (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-030 -
Summary In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server. In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

10 Aug 2021, 18:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CWE CWE-669
CPE cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
References (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-030 - (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-030 - Third Party Advisory

02 Aug 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-02 11:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-34574

Mitre link : CVE-2021-34574

CVE.ORG link : CVE-2021-34574


JSON object : View

Products Affected

mbconnectline

  • mymbconnect24
  • mbconnect24

helmholz

  • myrex24
  • myrex24.virtual
CWE
CWE-669

Incorrect Resource Transfer Between Spheres