First published: Tue Apr 14 2020(Updated: )
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote code execution in the backup-scheduler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mbconnectline Mbconnect24 | <=2.5.0 | |
Mbconnectline Mymbconnect24 | <=2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-10382.
The severity of CVE-2020-10382 is high with a severity value of 8.8.
All versions of the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software up to version 2.5.0 are affected by CVE-2020-10382.
CVE-2020-10382 is an authenticated remote code execution vulnerability in the backup-scheduler component of the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software.
To fix CVE-2020-10382, it is recommended to update the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software to version 2.5.1 or higher. Additionally, follow any security advice provided by the software vendor.