CVE-2022-22520: User enumeration vulnerability in MB connect line and Helmholz products
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22520?
CVE-2022-22520 is a vulnerability that allows a remote, unauthenticated attacker to enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24, and Helmholz myREX24 and myREX24.virtual.
How severe is CVE-2022-22520?
CVE-2022-22520 has a severity rating of medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2022-22520?
CVE-2022-22520 affects versions up to and including v2.11.2 of MB connect line mymbCONNECT24, mbCONNECT24, Helmholz myREX24, and Helmholz myREX24.virtual.
How can an attacker exploit CVE-2022-22520?
An attacker can exploit CVE-2022-22520 by sending specific requests to the webservice of the affected software to enumerate valid users.
Are there any references for CVE-2022-22520?
Yes, you can find references for CVE-2022-22520 at the following links: [VDE-2022-011](https://cert.vde.com/en/advisories/VDE-2022-011) and [VDE-2022-039](https://cert.vde.com/en/advisories/VDE-2022-039).