CVE-2024-45273

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
mb_connect_linembnet.mini
𝑥
≤ 2.2.13
mbconnectlinembnet_mbnet.rokey
𝑥
≤ 8.2.0
mbconnectlinembnet_hw1
𝑥
≤ 5.1.11
mbconnectlinembspider
𝑥
≤ 2.6.5
mbconnectlinembconnect24
𝑥
≤ 2.16.2
mbconnectlinemymbconnect24
𝑥
≤ 2.16.2
helmholzrex100
𝑥
≤ 2.2.13
helmholzrex_200
𝑥
≤ 8.2.0
helmholzrex250
𝑥
≤ 8.2.0
helmholzmyrex24_v2
𝑥
≤ 2.16.2
helmholzmyrex24.virtual
𝑥
≤ 2.16.2
helmholzrex300
𝑥
≤ 5.1.11
mbconnectlinembnet.mini_firmware
𝑥
< 2.3.1
helmholzmyrex24_v2_virtual_server
𝑥
< 2.16.3
helmholzrex_300_firmware
𝑥
≤ 5.1.11
helmholzrex_200_firmware
𝑥
< 8.2.1
helmholzrex_250_firmware
𝑥
< 8.2.1
helmholzrex_100_firmware
𝑥
< 2.3.1
mbconnectlinembconnect24
𝑥
< 2.16.3
mbconnectlinemymbconnect24
𝑥
< 2.16.3
mbconnectlinembspider_mdh_905_firmware
𝑥
≤ 2.6.5
mbconnectlinembspider_mdh_915_firmware
𝑥
≤ 2.6.5
mbconnectlinembspider_mdh_906_firmware
𝑥
≤ 2.6.5
mbconnectlinembspider_mdh_916_firmware
𝑥
≤ 2.6.5
mbconnectlinembnet_hw1_firmware
𝑥
≤ 5.1.11
mbconnectlinembnet_firmware
𝑥
< 8.2.1
mbconnectlinembnet.rokey_firmware
𝑥
< 8.2.1
𝑥
= Vulnerable software versions