VDE-2021-058
Last update
05/14/2025 15:00
Published at
12/08/2021 14:04
Vendor(s)
Helmholz GmbH & Co. KG
External ID
VDE-2021-058
CSAF Document
Summary
An issue was discovered in the myREX24 and myREX24-virtual software in all versions through V2.9.0.
Impact
Affected Product(s)
Model no. | Product name | Affected versions |
---|---|---|
myREX24 | Firmware <=2.9.0 | |
myREX24-virtual | Firmware <=2.9.0 |
Vulnerabilities
Expand / Collapse all
Published
09/22/2025 14:58
Severity
Weakness
Observable Response Discrepancy (CWE-204)
Summary
An unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
References
Remediation
Update myREX24/myREX24-virtual to 2.10.1
Revision History
Version | Date | Summary |
---|---|---|
1 | 12/08/2021 14:04 | initial revision |
2 | 05/14/2025 15:00 | Fix: added distribution |