CVE-2020-35566: Local file inclusion vulnerability in products of MB connect line and Helmholz
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35566?
CVE-2020-35566 has a severity rating of medium (5.3).
Which software versions are affected by CVE-2020-35566?
CVE-2020-35566 affects mbCONNECT24 and myREX24 versions up to and including v2.11.2.
How can an attacker exploit CVE-2020-35566?
An attacker can exploit CVE-2020-35566 by exploiting a Local File Inclusion vulnerability to read arbitrary JSON files.
Are there any advisories available for CVE-2020-35566?
Yes, advisories for CVE-2020-35566 are available at the following URLs: [https://cert.vde.com/en/advisories/VDE-2021-003](https://cert.vde.com/en/advisories/VDE-2021-003) and [https://cert.vde.com/en/advisories/VDE-2022-039](https://cert.vde.com/en/advisories/VDE-2022-039).
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-35566?
The CWE ID for CVE-2020-35566 is 706.