CVE-2020-12527: Improper Access Validation in products of MB connect line and Helmholz
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12527?
CVE-2020-12527 is a vulnerability discovered in MB connect line mymbCONNECT24, mbCONNECT24, Helmholz myREX24, and myREX24.virtual.
What is the severity of CVE-2020-12527?
The severity of CVE-2020-12527 is medium with a severity value of 6.5.
What is the affected software for CVE-2020-12527?
The affected software for CVE-2020-12527 includes MB connect line mymbCONNECT24, mbCONNECT24, Helmholz myREX24, and myREX24.virtual versions up to and including v2.11.2.
What is the vulnerability description of CVE-2020-12527?
CVE-2020-12527 is an improper access validation vulnerability that allows a logged-in user to shutdown or reboot devices in their account without proper permissions.
Are there any references available for CVE-2020-12527?
Yes, you can find references for CVE-2020-12527 at the following links: [Reference 1](https://cert.vde.com/en/advisories/VDE-2021-003) and [Reference 2](https://cert.vde.com/en/advisories/VDE-2022-039).