Password policy evasion in products of MB connect line and Helmholz
Vulnerability Description
In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34574
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- OTORIO reported the vulnerabilities to MB connect line.
References
More from MB connect line
View All →Affected Vendor
MB connect line
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.