CVE-2021-34574: Password policy evasion in products of MB connect line and Helmholz
In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-34574.
What is the severity level of CVE-2021-34574?
The severity level of CVE-2021-34574 is medium.
Which software versions are affected by CVE-2021-34574?
CVE-2021-34574 affects all versions up to and including v2.11.2 of mbCONNECT24, mymbCONNECT24, myREX24, and myREX24.virtual.
How can an attacker exploit CVE-2021-34574?
An authenticated attacker can exploit CVE-2021-34574 by intercepting and modifying the request to change their account password into a new password that violates the password policy.
Are there any references for CVE-2021-34574?
Yes, you can find references for CVE-2021-34574 at the following links: [VDE-2021-030](https://cert.vde.com/en/advisories/VDE-2021-030) and [VDE-2022-039](https://cert.vde.com/en/advisories/VDE-2022-039).