ZeroHour

CVE-2020-35557

CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

Vendors
mbconnectlinehelmholz
Products
mbconnect24, mymbconnect24, myrex24, myrex24.virtual
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.