CVE-2024-45273: MB connect line/Helmholz: Weak encryption of configuration file
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45273?
CVE-2024-45273 has been classified with a severity level that indicates potential risk due to unauthenticated local access allowing decryption of sensitive configuration files.
How do I fix CVE-2024-45273?
To fix CVE-2024-45273, upgrade to the latest firmware version that addresses the weak encryption implementation.
Who is affected by CVE-2024-45273?
CVE-2024-45273 affects devices running specific versions of firmware for products by Mbconnectline and Helmholz.
What are the risks associated with CVE-2024-45273?
The risks of CVE-2024-45273 include potential unauthorized access and compromise of device configurations, leading to further attacks.
Can CVE-2024-45273 be exploited remotely?
No, CVE-2024-45273 requires local access for exploitation, making it a concern primarily for environments with physical security vulnerabilities.