CVE-2024-45271

EUVD-2024-41404
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
mbconnectlinembnet.mini_firmware
𝑥
< 2.3.1
helmholzrex_100_firmware
𝑥
< 2.3.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mb_connect_linembnet.mini
𝑥
≤ 2.2.13
ADP
rex100helmholz
𝑥
≤ 2.2.13
ADP