VDE-2023-002
Last update
05/14/2025 15:00
Published at
05/15/2023 16:06
Vendor(s)
MB connect line GmbH
External ID
vde-2023-002
CSAF Document
Summary
Two vulnerabilites have been discovered in mbCONNECT24 and mbCONNECT24 in all versions through 2.13.3.
Impact
Please consult the CVE Entries.
Affected Product(s)
Model no. | Product name | Affected versions |
---|---|---|
mbCONNECT24 | Firmware <=2.13.3 | |
mymbCONNECT24 | Firmware <=2.13.3 |
Vulnerabilities
Expand / Collapse allMitigation
For CVE-2023-0985: If you have MFA enabled on the admin user, the password will still be set, but the attacker will be unable to login as the MFA is still in place.
Remediation
Update to latest Version: 2.13.4
Revision History
Version | Date | Summary |
---|---|---|
1 | 05/15/2023 16:06 | initial revision |
2 | 05/14/2025 15:00 | Fix: added distribution |