CVE-2024-45275

EUVD-2024-41408
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
mb_connect_linembnet.mini
𝑥
≤ 2.2.13
helmholzrex_100_firmware
𝑥
≤ 2.2.13
mbconnectlinembnet.mini_firmware
𝑥
< 2.3.1
helmholzrex_100_firmware
𝑥
< 2.3.1
𝑥
= Vulnerable software versions