Vulnerabilidades en MB connect line
82 resultadosCVE-2021-33527CRITICALOS Command Injection in mbDIALUP <= 3.9R0.0EPSS 4.5%CVE-2024-45274CRITICALMB connect line/Helmholz: Remote code execution via confnet serviceEPSS 1.5%CVE-2021-34575HIGHInformation Exposure in mymbCONNECT24, mbCONNECT24 <= 2.8.0EPSS 1.0%CVE-2020-12527MEDIUMImproper Access Validation in products of MB connect line and HelmholzEPSS 1.0%CVE-2021-34580HIGHRemote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0EPSS 1.0%CVE-2020-12528MEDIUMAn issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access valEPSS 0.8%CVE-2020-12529MEDIUMAn issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAPEPSS 0.8%CVE-2024-45275CRITICALMB connect line/Helmholz: Hardcoded user accounts with hard-coded passwordsEPSS 0.8%CVE-2023-0985HIGHHelmholz and MB Connect Line: Account takeover via password reset in multiple productsEPSS 0.8%CVE-2022-22520MEDIUMUser enumeration vulnerability in MB connect line and Helmholz productsEPSS 0.8%CVE-2021-34574MEDIUMPassword policy evasion in products of MB connect line and HelmholzEPSS 0.7%CVE-2025-41679MEDIUMUnauthenticated Buffer Overflow in Conftool Service Leading to Denial of ServiceEPSS 0.6%CVE-2020-12530MEDIUMAn issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in tEPSS 0.6%CVE-2024-45276HIGHMB connect line/Helmholz: tmp directory exposed via webserviceEPSS 0.6%CVE-2025-41688HIGHHigh Privilege RCE via LUA Sandbox EscapeEPSS 0.6%CVE-2024-45272HIGHMB connect line/Helmholz: Generation of weak passwords vulnerabilityEPSS 0.6%CVE-2025-41675HIGHRemote Command Injection via GET in Cloud Server Communication Script Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41674HIGHRemote Command Injection in diagnostic Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41673HIGHRemote Command Injection in send_sms Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41678MEDIUMSQL Injection via POST Requests Allowing Configuration Database ManipulationEPSS 0.6%