<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_mbconnectlinegmbh/10</id>
  <title>Most recent entries from csaf_mbconnectlinegmbh</title>
  <updated>2026-10-02T10:03:14.847963+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-003</id>
    <title>VDE-2021-003 — MB connect line: Multiple vulnerabilites in mymbCONNECT24 and mbCONNECT24 (Update A)</title>
    <updated>2022-09-07T10:46:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been found in mymbCONNECT24 and mbCONNECT24.
Update A, 2022-09-07:</p>
<p>Affected Products: updated affected versions due to incomplete fixes of some CVEs. See Solution for details.
Solution: updated version information.
Solution: Added Fix for CVE-2020-35561.
Solution: Added MFA remark for CVE-2020-35565.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-003"/>
    <published>2022-09-07T10:46:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-011</id>
    <title>VDE-2022-011 — MB connect line: Unauthenticated user enumeration in mbCONNECT24 and mymbCONNECT24</title>
    <updated>2022-09-07T12:50:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-011"/>
    <published>2022-09-07T12:50:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-012</id>
    <title>VDE-2023-012 — MB connect line: Cross-site Scripting vulnerability in mbNET/mbNET.rokey</title>
    <updated>2023-08-17T12:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-012"/>
    <published>2023-08-17T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-042</id>
    <title>VDE-2024-042 — MB connect line: Multiple products are vulnerable to regreSSHion</title>
    <updated>2023-08-17T12:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-042"/>
    <published>2023-08-17T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-041</id>
    <title>VDE-2023-041 — MB connect line: Vulnerability allows access to non-critical information in mbCONNECT24 and mymbCONNECT24</title>
    <updated>2023-10-16T08:38:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-041"/>
    <published>2023-10-16T08:38:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-030</id>
    <title>VDE-2024-030 — MB connect line: mbNET.mini vulnerable to OS command injection</title>
    <updated>2024-07-03T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There exists a vulnerability in all mbNET.mini devices with firmware &lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.
Update: 03.07.2024 3:30 pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-030"/>
    <published>2024-07-03T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-035</id>
    <title>VDE-2020-035 — MB connect line: Multiple Vulnerabilities in mymbCONNECT24 and mbCONNECT24 &lt;= v2.6.1</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiples issues exist in mymbCONNECT24 and mbCONNECT24</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-035"/>
    <published>2020-09-18T12:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-012</id>
    <title>VDE-2021-012 — MB connect line: multiple products partially affected by DNSpooq</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple issues have been identified in dnsmasq &lt; 2.83</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-012"/>
    <published>2021-04-26T08:04:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-017</id>
    <title>VDE-2021-017 — MB connect line: Privilege escalation in mbDIALUP</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple Vulnerabilities in mbConnect24serv (a software service of mbDIALUP) can lead to arbitrary code execution due to improper privilege management.</p>
<p>Update A, 2021-11-24</p>
<p>corrected fixed version in solution from 3.9R0.4 to 3.9R0.5</p>
<p>Update B, 2022-03-28</p>
<p>Updated CVSS score from CVE-2021-33527 from 7.8 to 9.8 due to new information about the vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-017"/>
    <published>2021-07-22T11:35:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-031</id>
    <title>VDE-2021-031 — MB connect line: Apache Guacamole related vulnerabilities in mbCONNECT24</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Two vulnerabilities in mbCONNECT24 and mymbCONNECT24 can lead to information disclosure and arbitrary code execution.</p>
<p>Please consult the CVE entries for details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-031"/>
    <published>2021-07-22T11:33:00+00:00</published>
  </entry>
</feed>
