ZeroHour

CVE-2022-22520

CVSS 3.1
5.3 medium
EPSS
<1%p57
Published
()
Modified
Description

A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.

Vendors
mbconnectlinehelmholz
Products
mbconnect24, mymbconnect24, myrex24, myrex24.virtual
Weakness
CWE-204
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.