A
n unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
References
| Link | Resource |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-056 | Third Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2024-066 | Third Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2024-068 | Third Party Advisory |
| https://cert.vde.com/en/advisories/VDE-2024-069 | Third Party Advisory |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-062.txt |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
| AND |
|
Configuration 13 (hide)
| AND |
|
Configuration 14 (hide)
| AND |
|
History
21 Nov 2024, 09:37
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
| References |
|
17 Oct 2024, 17:41
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:helmholz:rex_200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbspider_mdh_915_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbspider_mdh_906_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbspider_mdh_916_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbspider_mdh_905_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbspider_mdh_916:-:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex_300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_250:-:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbnet:-:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_300:-:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbnet.rokey:-:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbspider_mdh_915:-:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbnet.rokey_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:* cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbspider_mdh_906:-:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbnet_hw1:-:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbnet_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:helmholz:myrex24_v2_virtual_server:*:*:*:*:*:*:*:* cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:* cpe:2.3:o:mbconnectline:mbnet_hw1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:helmholz:rex_250_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:mbconnectline:mbspider_mdh_905:-:*:*:*:*:*:*:* |
|
| Summary |
|
|
| First Time |
Helmholz rex 300
Mbconnectline mbspider Mdh 905 Firmware Mbconnectline Helmholz rex 100 Firmware Mbconnectline mbspider Mdh 916 Helmholz myrex24 V2 Virtual Server Mbconnectline mbnet Firmware Mbconnectline mbspider Mdh 905 Helmholz rex 300 Firmware Mbconnectline mbnet Hw1 Firmware Mbconnectline mbspider Mdh 916 Firmware Mbconnectline mbspider Mdh 915 Firmware Helmholz rex 250 Firmware Mbconnectline mbnet.mini Firmware Mbconnectline mbspider Mdh 906 Firmware Helmholz rex 200 Firmware Helmholz rex 200 Mbconnectline mbnet.rokey Firmware Mbconnectline mbspider Mdh 906 Mbconnectline mbspider Mdh 915 Helmholz rex 100 Mbconnectline mbnet Hw1 Mbconnectline mbnet.mini Helmholz rex 250 Mbconnectline mymbconnect24 Mbconnectline mbnet Mbconnectline mbconnect24 Mbconnectline mbnet.rokey Helmholz |
|
| References | () https://cert.vde.com/en/advisories/VDE-2024-056 - Third Party Advisory | |
| References | () https://cert.vde.com/en/advisories/VDE-2024-066 - Third Party Advisory | |
| References | () https://cert.vde.com/en/advisories/VDE-2024-068 - Third Party Advisory | |
| References | () https://cert.vde.com/en/advisories/VDE-2024-069 - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-326 |
15 Oct 2024, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-15 11:15
Updated : 2024-11-21 09:37
NVD link : CVE-2024-45273
Mitre link : CVE-2024-45273
CVE.ORG link : CVE-2024-45273
JSON object : View
Products Affected
- mymbconnect24
- mbspider_mdh_905_firmware
- mbspider_mdh_906_firmware
- mbnet_firmware
- mbnet.rokey_firmware
- mbspider_mdh_916
- mbnet.mini_firmware
- mbnet
- mbspider_mdh_905
- mbnet.mini
- mbspider_mdh_916_firmware
- mbnet.rokey
- mbspider_mdh_915
- mbnet_hw1_firmware
- mbconnect24
- mbnet_hw1
- mbspider_mdh_915_firmware
- mbspider_mdh_906