Article No° | Product Name | Affected Version(s) |
---|---|---|
mbCONNECT24 | < 2.16.5 | |
mymbCONNECT24 | < 2.18.0 | |
mymbCONNECT24 | < 2.18.0 | |
mymbCONNECT24 | < 2.16.5 |
Two vulnerabilities in mbCONNECT24/mymbCONNECT24 can lead to user enumeration an password bypass.
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CVE-2025-3091: An attacker in possession of the second factor for an user can login as that user without knowledge of the password (first factor)
CVE-2025-3092: An unprotected endpoint can by used to enumerate valid user names.
Remediation
CVE-2025-3091: Update to latest version: 2.16.5
CVE-2025-3092: Update to latest version: 2.18.0
CERT@VDE coordinated with MB connect line
Reporting: Peter Husted Simonsen, Irwin Przeperski from Eviden