Lucene search

K
cvelistCERTVDECVELIST:CVE-2021-34574
HistorySep 07, 2022 - 12:00 a.m.

CVE-2021-34574 Password policy evasion in products of MB connect line and Helmholz

2022-09-0700:00:00
CWE-669
CERTVDE
www.cve.org
cve-2021-34574
password policy evasion
mb connect line
helmholz
intercepting request
authenticated attacker
password change
server security

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

4.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.

CNA Affected

[
  {
    "product": "mymbCONNECT24",
    "vendor": "MB connect line",
    "versions": [
      {
        "lessThanOrEqual": "2.11.2",
        "status": "affected",
        "version": "2",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "mbCONNECT24",
    "vendor": "MB connect line",
    "versions": [
      {
        "lessThanOrEqual": "2.11.2",
        "status": "affected",
        "version": "2",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "myREX24",
    "vendor": "Helmholz",
    "versions": [
      {
        "lessThanOrEqual": "2.11.2",
        "status": "affected",
        "version": "2",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "myREX24.virtual",
    "vendor": "Helmholz",
    "versions": [
      {
        "lessThanOrEqual": "2.11.2",
        "status": "affected",
        "version": "2",
        "versionType": "custom"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

4.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

Related for CVELIST:CVE-2021-34574