Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-068
März 6, 2026, 9:00 vorm.
Multiple vulnerabilities have been discovered in MB connect line products that could allow RCE or unauthorized file access. CVE-2024-45272 affects the mbCONNECT24 and mymbCONNECT24 products. CVE-2024-45273 affects the mbNET/mbNET.rokey, mbCONNECT24, …
VDE-2024-030
Juli 3, 2024, 11:00 vorm.
There exists a vulnerability in all mbNET.mini devices with firmware <= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests. Update: 03.07.2024 3:30 pm …
VDE-2023-041
Okt. 16, 2023, 10:38 vorm.
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain …
VDE-2023-012
Aug. 17, 2023, 2:00 nachm.
A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.
VDE-2024-042
Aug. 17, 2023, 2:00 nachm.
Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".
VDE-2023-002
Mai 14, 2025, 3:00 nachm.
Two vulnerabilites have been discovered in mbCONNECT24 and mbCONNECT24 in all versions through 2.13.3.
VDE-2022-011
Sept. 7, 2022, 2:50 nachm.
An issue was discovered in the mymbCONNECT24 and mbCONNECT24 software in all versions through V2.11.2.
VDE-2021-030
Juni 6, 2025, 9:00 vorm.
Two issues have been discovered in mymbCONNECT24 and mbCONNECT24 in all versionsincluding V2.8.0. Updated affected versions (and solution) due to incomplete fixes in previous versions