CVE-2020-35567: High severity mbconnectline mymbconnect24 vulnerability
Published Feb 16, 2021
·Updated
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.2
Mbconnectline Mymbconnect24<=2.6.2
Event History
Feb 16, 2021
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35567.
2
What is the severity of CVE-2020-35567?
CVE-2020-35567 has a severity level of 7.8 out of 10, which is considered high.
3
What software is affected by CVE-2020-35567?
MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 versions up to 2.6.2 are affected by CVE-2020-35567.
4
What is the impact of CVE-2020-35567?
CVE-2020-35567 allows an attacker to access the database using a shared password.
5
How can I fix CVE-2020-35567?
To fix CVE-2020-35567, update MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 to version 2.6.2 or later and make sure to use unique passwords for database access.