CVE-2024-45273

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:helmholz:myrex24_v2_virtual_server:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:helmholz:rex_300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_300:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:helmholz:rex_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:helmholz:rex_250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_250:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mbconnectline:mbspider_mdh_905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_905:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mbconnectline:mbspider_mdh_915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_915:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mbconnectline:mbspider_mdh_906_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_906:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:mbconnectline:mbspider_mdh_916_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_916:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:mbconnectline:mbnet_hw1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet_hw1:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:mbconnectline:mbnet_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:mbconnectline:mbnet.rokey_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet.rokey:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:37

Type Values Removed Values Added
References
  • () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-062.txt -
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 8.4

17 Oct 2024, 17:41

Type Values Removed Values Added
First Time Mbconnectline
Mbconnectline mbnet.mini
Mbconnectline mbspider Mdh 906 Firmware
Mbconnectline mbspider Mdh 905
Mbconnectline mbspider Mdh 906
Mbconnectline mbnet Hw1 Firmware
Mbconnectline mbspider Mdh 916 Firmware
Mbconnectline mbnet Firmware
Mbconnectline mbspider Mdh 905 Firmware
Mbconnectline mymbconnect24
Helmholz rex 300
Mbconnectline mbconnect24
Mbconnectline mbnet.mini Firmware
Mbconnectline mbnet.rokey
Helmholz rex 250 Firmware
Mbconnectline mbnet
Mbconnectline mbspider Mdh 916
Helmholz rex 250
Helmholz rex 300 Firmware
Helmholz rex 100
Helmholz rex 200 Firmware
Mbconnectline mbnet.rokey Firmware
Mbconnectline mbnet Hw1
Helmholz myrex24 V2 Virtual Server
Mbconnectline mbspider Mdh 915
Mbconnectline mbspider Mdh 915 Firmware
Helmholz rex 200
Helmholz rex 100 Firmware
Helmholz
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 7.8
References () https://cert.vde.com/en/advisories/VDE-2024-056 - () https://cert.vde.com/en/advisories/VDE-2024-056 - Third Party Advisory
References () https://cert.vde.com/en/advisories/VDE-2024-066 - () https://cert.vde.com/en/advisories/VDE-2024-066 - Third Party Advisory
References () https://cert.vde.com/en/advisories/VDE-2024-068 - () https://cert.vde.com/en/advisories/VDE-2024-068 - Third Party Advisory
References () https://cert.vde.com/en/advisories/VDE-2024-069 - () https://cert.vde.com/en/advisories/VDE-2024-069 - Third Party Advisory
CWE CWE-326
CPE cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbnet_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_916:-:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:rex_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbspider_mdh_916_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbnet_hw1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbnet.rokey_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:rex_250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_250:-:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet_hw1:-:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbspider_mdh_905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:rex_300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbspider_mdh_915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_915:-:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_905:-:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_200:-:*:*:*:*:*:*:*
cpe:2.3:o:mbconnectline:mbspider_mdh_906_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet:-:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbnet.rokey:-:*:*:*:*:*:*:*
cpe:2.3:h:mbconnectline:mbspider_mdh_906:-:*:*:*:*:*:*:*
cpe:2.3:h:helmholz:rex_300:-:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24_v2_virtual_server:*:*:*:*:*:*:*:*
Summary
  • (es) Un atacante local no autenticado puede descifrar el archivo de configuración del dispositivo y, por lo tanto, comprometer el dispositivo debido a una implementación débil del cifrado utilizado.

15 Oct 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 11:15

Updated : 2024-11-21 09:37


NVD link : CVE-2024-45273

Mitre link : CVE-2024-45273

CVE.ORG link : CVE-2024-45273


JSON object : View

Products Affected

helmholz

  • rex_300_firmware
  • rex_200
  • rex_250
  • myrex24_v2_virtual_server
  • rex_100_firmware
  • rex_100
  • rex_250_firmware
  • rex_200_firmware
  • rex_300

mbconnectline

  • mbnet_firmware
  • mbspider_mdh_906
  • mbconnect24
  • mbnet
  • mbspider_mdh_916_firmware
  • mbspider_mdh_905_firmware
  • mbspider_mdh_905
  • mbnet_hw1_firmware
  • mbnet.rokey_firmware
  • mbnet_hw1
  • mbnet.mini_firmware
  • mbnet.mini
  • mbspider_mdh_916
  • mbnet.rokey
  • mbspider_mdh_906_firmware
  • mymbconnect24
  • mbspider_mdh_915_firmware
  • mbspider_mdh_915
CWE
CWE-261

Weak Encoding for Password

CWE-326

Inadequate Encryption Strength