CVE-2020-35564: High severity mbconnectline mymbconnect24 vulnerability
Published Feb 16, 2021
·Updated
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.2
Mbconnectline Mymbconnect24<=2.6.2
Event History
Feb 16, 2021
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35564.
2
What is the severity of CVE-2020-35564?
The severity of CVE-2020-35564 is high, with a score of 7.5.
3
Which software is affected by CVE-2020-35564?
MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 versions up to and including 2.6.2 are affected.
4
What is the CWE ID of CVE-2020-35564?
The CWE ID of CVE-2020-35564 is 74.
5
How can I fix the vulnerability CVE-2020-35564?
To fix the vulnerability CVE-2020-35564, update MB CONNECT LINE mymbCONNECT24 or mbCONNECT24 to version 2.6.3 or later.