CVE-2024-45274: MB connect line/Helmholz: Remote code execution via confnet service
Published Oct 15, 2024
·Updated
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Affected Software
4 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.1
Mbconnectline Mbnet.mini
All of the following
Helmholz Rex 100 Firmware<2.3.1
Helmholz Rex 100
Event History
Oct 15, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45274?
CVE-2024-45274 is considered a critical vulnerability due to its ability to allow unauthenticated remote code execution.
2
How do I fix CVE-2024-45274?
To fix CVE-2024-45274, update the affected firmware to version 2.3.1 or later.
3
What devices are affected by CVE-2024-45274?
CVE-2024-45274 affects the Mbconnectline Mbnet.mini and Helmholz Rex 100 firmware prior to version 2.3.1.
4
Can CVE-2024-45274 be exploited remotely?
Yes, CVE-2024-45274 can be exploited remotely by an unauthenticated attacker via UDP.
5
What are the potential impacts of CVE-2024-45274?
The potential impacts of CVE-2024-45274 include arbitrary code execution and complete system compromise.