CVE-2020-35570: Foreced Browsing vulnerability in products of MB connect line and Helmholz
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35570.
What is the severity of CVE-2020-35570?
The severity of CVE-2020-35570 is medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2020-35570?
The affected software versions are mbCONNECT24 2.11.2, mymbCONNECT24 2.11.2, myREX24 2.11.2, and myREX24.virtual 2.11.2.
How can an attacker exploit CVE-2020-35570?
An unauthenticated attacker can exploit CVE-2020-35570 by accessing files that should have been restricted through forceful browsing.
Are there any references available for CVE-2020-35570?
Yes, you can find references for CVE-2020-35570 at the following links: [reference1](https://cert.vde.com/en/advisories/VDE-2021-003), [reference2](https://cert.vde.com/en/advisories/VDE-2022-039), [reference3](https://mbconnectline.com/security-advice/).