CVE-2025-3091
MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Helmholz · myREX24Helmholz · myREX24.virtualMB connect line · mbCONNECT24MB connect line · mymbCONNECT24¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →