ZeroHour

CVE-2020-35570

CVSS 3.1
5.3 medium
EPSS
1%p68
Published
()
Modified
Description

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

Vendors
mbconnectlinehelmholz
Products
mbconnect24, mymbconnect24, myrex24, myrex24.virtual
Weakness
CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.