First published: Tue Oct 15 2024(Updated: )
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Helmholz Myrex24 V2 Virtual Server | <2.16.3 | |
All of | ||
Helmholz Rex 300 Firmware | <=5.1.11 | |
Helmholz Rex 300 | ||
All of | ||
Helmholz Rex 200 Firmware | <8.2.1 | |
Helmholz REX 200 | ||
All of | ||
Helmholz Rex 250 Firmware | <8.2.1 | |
Helmholz Rex 250 | ||
Mbconnectline Mbconnect24 | <2.16.3 | |
Mbconnectline Mymbconnect24 | <2.16.3 | |
All of | ||
Mbconnectline Mbspider Mdh 905 Firmware | <=2.6.5 | |
Mbconnectline Mbspider Mdh 905 | ||
All of | ||
Mbconnectline Mbspider Mdh 915 Firmware | <=2.6.5 | |
Mbconnectline Mbspider Mdh 915 | ||
All of | ||
Mbconnectline Mbspider Mdh 906 Firmware | <=2.6.5 | |
Mbconnectline Mbspider Mdh 906 | ||
All of | ||
Mbconnectline Mbspider Mdh 916 Firmware | <=2.6.5 | |
Mbconnectline Mbspider Mdh 916 | ||
All of | ||
Mbconnectline Mbnet Hw1 Firmware | <=5.1.11 | |
Mbconnectline Mbnet Hw1 | ||
All of | ||
Mbconnectline Mbnet Firmware | <8.2.1 | |
Mbconnectline Mbnet | ||
All of | ||
Mbconnectline Mbnet.rokey Firmware | <8.2.1 | |
Mbconnectline Mbnet.rokey |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45272 has a high severity rating due to the potential for successful brute-force attacks on remote service portal credentials.
To fix CVE-2024-45272, implement strong password policies and account lockout mechanisms to prevent brute-force attacks.
CVE-2024-45272 affects various models of the Helmholz Myrex24 V2 Virtual Server and Mbconnectline products running specific firmware versions.
Yes, CVE-2024-45272 can be exploited remotely by unauthenticated attackers targeting the credentials of the remote service portal.
Exploitation of CVE-2024-45272 can lead to unauthorized access and loss of connection to the remote service.