<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_mbconnectlinegmbh</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:39:58 +0000</lastBuildDate>
    <item>
      <title>VDE-2021-003 — MB connect line: Multiple vulnerabilites in mymbCONNECT24 and mbCONNECT24 (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-003</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been found in mymbCONNECT24 and mbCONNECT24.
Update A, 2022-09-07:&lt;/p&gt;
&lt;p&gt;Affected Products: updated affected versions due to incomplete fixes of some CVEs. See Solution for details.
Solution: updated version information.
Solution: Added Fix for CVE-2020-35561.
Solution: Added MFA remark for CVE-2020-35565.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been found in mymbCONNECT24 and mbCONNECT24.
Update A, 2022-09-07:&lt;/p&gt;
&lt;p&gt;Affected Products: updated affected versions due to incomplete fixes of some CVEs. See Solution for details.
Solution: updated version information.
Solution: Added Fix for CVE-2020-35561.
Solution: Added MFA remark for CVE-2020-35565.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-003</guid>
      <pubDate>Wed, 07 Sep 2022 10:46:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-011 — MB connect line: Unauthenticated user enumeration in mbCONNECT24 and mymbCONNECT24</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-011</link>
      <description>&lt;p&gt;A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-011</guid>
      <pubDate>Wed, 07 Sep 2022 12:50:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-012 — MB connect line: Cross-site Scripting vulnerability in mbNET/mbNET.rokey</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-012</link>
      <description>&lt;p&gt;A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-012</guid>
      <pubDate>Thu, 17 Aug 2023 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-042 — MB connect line: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-042</link>
      <description>&lt;p&gt;Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-042</guid>
      <pubDate>Thu, 17 Aug 2023 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-041 — MB connect line: Vulnerability allows access to non-critical information in mbCONNECT24 and mymbCONNECT24</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-041</link>
      <description>&lt;p&gt;In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-041</guid>
      <pubDate>Mon, 16 Oct 2023 08:38:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-030 — MB connect line: mbNET.mini vulnerable to OS command injection</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-030</link>
      <description>&lt;p&gt;There exists a vulnerability in all mbNET.mini devices with firmware &amp;lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.
Update: 03.07.2024 3:30 pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There exists a vulnerability in all mbNET.mini devices with firmware &amp;lt;= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests.
Update: 03.07.2024 3:30 pm 
In section Reported by Sebastian Dietz (CyberDanube) was added.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-030</guid>
      <pubDate>Wed, 03 Jul 2024 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-035 — MB connect line: Multiple Vulnerabilities in mymbCONNECT24 and mbCONNECT24 &lt;= v2.6.1</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-035</link>
      <description>&lt;p&gt;Multiples issues exist in mymbCONNECT24 and mbCONNECT24&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiples issues exist in mymbCONNECT24 and mbCONNECT24&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-035</guid>
      <pubDate>Fri, 18 Sep 2020 12:30:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-012 — MB connect line: multiple products partially affected by DNSpooq</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-012</link>
      <description>&lt;p&gt;Multiple issues have been identified in dnsmasq &amp;lt; 2.83&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple issues have been identified in dnsmasq &amp;lt; 2.83&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-012</guid>
      <pubDate>Mon, 26 Apr 2021 08:04:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-017 — MB connect line: Privilege escalation in mbDIALUP</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-017</link>
      <description>&lt;p&gt;Multiple Vulnerabilities in mbConnect24serv (a software service of mbDIALUP) can lead to arbitrary code execution due to improper privilege management.&lt;/p&gt;
&lt;p&gt;Update A, 2021-11-24&lt;/p&gt;
&lt;p&gt;corrected fixed version in solution from 3.9R0.4 to 3.9R0.5&lt;/p&gt;
&lt;p&gt;Update B, 2022-03-28&lt;/p&gt;
&lt;p&gt;Updated CVSS score from CVE-2021-33527 from 7.8 to 9.8 due to new information about the vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Vulnerabilities in mbConnect24serv (a software service of mbDIALUP) can lead to arbitrary code execution due to improper privilege management.&lt;/p&gt;
&lt;p&gt;Update A, 2021-11-24&lt;/p&gt;
&lt;p&gt;corrected fixed version in solution from 3.9R0.4 to 3.9R0.5&lt;/p&gt;
&lt;p&gt;Update B, 2022-03-28&lt;/p&gt;
&lt;p&gt;Updated CVSS score from CVE-2021-33527 from 7.8 to 9.8 due to new information about the vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-017</guid>
      <pubDate>Thu, 22 Jul 2021 11:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-031 — MB connect line: Apache Guacamole related vulnerabilities in mbCONNECT24</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-031</link>
      <description>&lt;p&gt;Two vulnerabilities in mbCONNECT24 and mymbCONNECT24 can lead to information disclosure and arbitrary code execution.&lt;/p&gt;
&lt;p&gt;Please consult the CVE entries for details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two vulnerabilities in mbCONNECT24 and mymbCONNECT24 can lead to information disclosure and arbitrary code execution.&lt;/p&gt;
&lt;p&gt;Please consult the CVE entries for details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-031</guid>
      <pubDate>Thu, 22 Jul 2021 11:33:00 +0000</pubDate>
    </item>
  </channel>
</rss>
