CVE-2024-45276: MB connect line/Helmholz: tmp directory exposed via webservice
Published Oct 15, 2024
·Updated
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
Affected Software
4 affected components
All of the following
Mbconnectline Mbnet.mini Firmware<2.3.1
Mbconnectline Mbnet.mini
All of the following
Helmholz Rex 100 Firmware<2.3.1
Helmholz Rex 100
Event History
Oct 15, 2024
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45276?
CVE-2024-45276 has been rated as a high severity vulnerability due to the risk of unauthorized file access.
2
Who is affected by CVE-2024-45276?
CVE-2024-45276 affects versions of Mbconnectline Mbnet.mini Firmware and Helmholz Rex 100 Firmware up to 2.3.1.
3
How do I fix CVE-2024-45276?
To mitigate CVE-2024-45276, update the affected firmware to a version that includes the security patch.
4
Can CVE-2024-45276 be exploited remotely?
Yes, CVE-2024-45276 can be exploited by unauthenticated remote attackers, allowing them to access sensitive files.
5
What are the implications of CVE-2024-45276?
CVE-2024-45276 could lead to unauthorized disclosure of sensitive information stored in the /tmp directory.