CVE-2024-45271: MB connect line/Helmholz: Remote code execution due to improper input validation
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45271?
CVE-2024-45271 is considered a critical vulnerability due to the potential for unauthenticated local attackers to gain admin privileges.
How do I fix CVE-2024-45271?
To address CVE-2024-45271, ensure proper input validation mechanisms are implemented and restrict access to configuration file deployment.
Who is affected by CVE-2024-45271?
CVE-2024-45271 affects users of the Mbconnectline Mbnet.mini firmware versions prior to 2.3.1 and Helmholz Rex 100 firmware versions prior to 2.3.1.
What could be the impact of exploiting CVE-2024-45271?
Exploitation of CVE-2024-45271 could lead to unauthorized access and control over affected devices by local attackers.
Is CVE-2024-45271 remotely exploitable?
CVE-2024-45271 requires local access for exploitation, therefore it is not remotely exploitable.