CVE-2023-1779

Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2023-008/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*

History

02 Oct 2024, 06:15

Type Values Removed Values Added
CWE CWE-200 CWE-863

15 Jun 2023, 12:36

Type Values Removed Values Added
First Time Mbconnectline
Mbconnectline mbconnect24
Mbconnectline mymbconnect24
CPE cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
CWE CWE-200 NVD-CWE-noinfo
References (MISC) https://cert.vde.com/en/advisories/VDE-2023-008/ - (MISC) https://cert.vde.com/en/advisories/VDE-2023-008/ - Third Party Advisory

06 Jun 2023, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-06 11:15

Updated : 2024-10-02 06:15


NVD link : CVE-2023-1779

Mitre link : CVE-2023-1779

CVE.ORG link : CVE-2023-1779


JSON object : View

Products Affected

mbconnectline

  • mbconnect24
  • mymbconnect24
CWE
CWE-863

Incorrect Authorization

NVD-CWE-noinfo