CVE-2020-10384: High severity mbconnectline mymbconnect24 vulnerability
Published Apr 14, 2020
·Updated
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.1
Mbconnectline Mymbconnect24<=2.6.1
Event History
Apr 14, 2020
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10384?
CVE-2020-10384 is a local privilege escalation vulnerability in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software.
2
What is the severity of CVE-2020-10384?
The severity of CVE-2020-10384 is high, with a CVSS score of 7.8.
3
How does CVE-2020-10384 affect the software?
CVE-2020-10384 affects the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions up to 2.6.1.
4
What is the CWE (Common Weakness Enumeration) ID for CVE-2020-10384?
The CWE ID for CVE-2020-10384 is 269.
5
How can I fix CVE-2020-10384?
To fix CVE-2020-10384, it is recommended to update the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software to version 2.6.2 or newer.