CVE-2024-45275
MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Los dispositivos contienen dos cuentas de usuario codificadas con contraseñas codificadas que permiten a un atacante remoto no autenticado tener control total de los dispositivos afectados.
*Credits:
Moritz Abrell, SySS GmbH
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-08-26 CVE Reserved
- 2024-10-15 CVE Published
- 2024-10-16 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2024-056 | ||
https://cert.vde.com/en/advisories/VDE-2024-066 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
MB Connect Line Search vendor "MB Connect Line" | MbNET.mini Search vendor "MB Connect Line" for product "MbNET.mini" | >= 0.0.0 <= 2.2.13 Search vendor "MB Connect Line" for product "MbNET.mini" and version " >= 0.0.0 <= 2.2.13" | en |
Affected
| ||||||
Helmholz Search vendor "Helmholz" | REX100 Search vendor "Helmholz" for product "REX100" | >= 0.0.0 <= 2.2.13 Search vendor "Helmholz" for product "REX100" and version " >= 0.0.0 <= 2.2.13" | en |
Affected
|