In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mbconnect24 | Mbconnectline | * | 2.11.2 (including) |
Mymbconnect24 | Mbconnectline | * | 2.11.2 (including) |