MB connect line mbCONNECT24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*
- < 2.16.5
A vulnerability exists in MB Connect Line's mbCONNECT24 and mymbCONNECT24 products, as well as in Helmholz's myREX24 and myREX24.virtual offerings, all prior to specified versions. This vulnerability allows unauthenticated remote attackers to enumerate valid usernames through an unprotected endpoint.
Exploitation of this vulnerability allows for user enumeration, potentially leading to targeted attacks against valid user accounts.
Users are advised to update to the latest version of the respective product: MB Connect Line users should update to version 2.18.0, while Helmholz users should also update to version 2.18.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.