Article No° | Product Name | Affected Version(s) |
---|---|---|
myREX24 V2 | <= 2.16.2 | |
myREX24.virtual | <= 2.16.2 | |
REX200/250 | <= 8.2.0 | |
REX300 | <= 5.1.11 |
Multiple vulnerabilities have been discovered in Helmholz products that could allow RCE or unauthorized file access. CVE-2024-45272 affects the myREX24 V2 and myREX24.virtual products, while CVE-2024-45273 affects the REX200/250, myREX24 V2, myREX24.virtual and REX300 products.
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
CVE-2024-45272 allows brute-force attacks against remote credentials with a high probability of success.
CVE-2024-45273 allows undetectable tampering and manipulation of encrypted configuration files.
Remediation
Note: REX 300 devices are EOL and will not receive any further updates.
CERT@VDE coordinated with Helmholz
Reported by Moritz Abrell of SySS GmbH