Remote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.0%
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
In short
An attacker can discover valid usernames on mymbCONNECT24 and mbCONNECT24 systems by observing how the server responds to fake login attempts. This helps attackers identify real accounts to target for further attacks.
Technical detail
The application returns different HTTP responses for valid versus invalid usernames during authentication, allowing unauthenticated enumeration via timing or response differentiation attacks. This information disclosure (CWE-204) enables attackers to build a list of legitimate users for subsequent credential-based or brute-force attacks against affected versions up to 2.9.0.
Summary generated and translated by AI from the official description.
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N