CVE-2023-4834
Published: Oct 16, 2023
Modified: Sep 16, 2024
CVSS v3.1
4.3
Description
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.
| Vendor | Product | Versions |
|---|---|---|
Red Lion Europe | mbCONNECT24 | affected 0 - <= 2.14.2 |
Red Lion Europe | mymbCONNECT24 | affected 0 - <= 2.14.2 |
Helmholz | myREX24 | affected 0 - <= 2.14.2 |
Helmholz | myREX24.virtual | affected 0 - <= 2.14.2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now