{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"OTORIO","summary":"reporting"}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Two issues have been discovered in mymbCONNECT24 and mbCONNECT24 in all versionsincluding V2.8.0.\n\nUpdated affected versions (and solution) due to incomplete fixes in previous versions","title":"Summary"},{"category":"description","text":"CVE-2021-34575: Update to 2.9.0\n\nCVE-2021-34574: Update to 2.12.1","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"self","summary":"VDE-2021-030: MB connect line: two vulnerabilities in mymbCONNECT24, mbCONNECT24 (Update A) - HTML","url":"https://certvde.com/en/advisories/VDE-2021-030/"},{"category":"self","summary":"VDE-2021-030: MB connect line: two vulnerabilities in mymbCONNECT24, mbCONNECT24 (Update A) - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-030.json"},{"category":"external","summary":"Vendor PSIRT","url":"https://mbconnectline.com"},{"category":"external","summary":"CERT@VDE Security Advisories for MB connect line GmbH","url":"https://certvde.com/en/advisories/vendor/mbconnectline/"}],"title":"MB connect line: two vulnerabilities in mymbCONNECT24, mbCONNECT24 (Update A)","tracking":{"aliases":["VDE-2021-030"],"current_release_date":"2025-06-06T07:00:00.000Z","generator":{"date":"2025-06-06T07:43:36.709Z","engine":{"name":"Secvisogram","version":"2.5.27"}},"id":"VDE-2021-030","initial_release_date":"2022-09-07T10:48:00.000Z","revision_history":[{"date":"2022-09-07T10:48:00.000Z","number":"1.0.0","summary":"Initial revision."},{"date":"2022-09-07T14:00:00.000Z","number":"1.1.0","summary":"Update A"},{"date":"2025-06-06T07:00:00.000Z","number":"1.2.0","summary":"Fixed CVE-IDs in Solution/Remidiation"}],"status":"final","version":"1.2.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<=2.11.2","product":{"name":"mbCONNECT24 <=2.11.2","product_id":"CSAFPID-51001"}},{"category":"product_version","name":"2.12.1","product":{"name":"mbCONNECT24 2.12.1","product_id":"CSAFPID-52001"}},{"category":"product_version","name":"2.9.0","product":{"name":"MB connect line Software mbCONNECT24 2.9.0","product_id":"CSAFPID-52002"}}],"category":"product_name","name":"mbCONNECT24"},{"branches":[{"category":"product_version_range","name":"<=2.11.2","product":{"name":"mymbCONNECT24 <=2.11.2","product_id":"CSAFPID-51002"}},{"category":"product_version","name":"2.12.1","product":{"name":"mymbCONNECT24 2.12.1","product_id":"CSAFPID-52003"}},{"category":"product_version","name":"2.9.0","product":{"name":"MB connect line Software mymbCONNECT24 2.9.0","product_id":"CSAFPID-52004"}}],"category":"product_name","name":"mymbCONNECT24"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-51001","CSAFPID-51002"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-52001","CSAFPID-52002","CSAFPID-52003","CSAFPID-52004"],"summary":"Fixed products."}]},"vulnerabilities":[{"cve":"CVE-2021-34574","cwe":{"id":"CWE-669","name":"Incorrect Resource Transfer Between Spheres"},"notes":[{"category":"description","text":"In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates the password policy by intercepting and modifying the request that is send to the server.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-52001","CSAFPID-52003"],"known_affected":["CSAFPID-51001","CSAFPID-51002"]},"remediations":[{"category":"vendor_fix","details":"CVE-2021-34575: Update to 2.9.0\n\nCVE-2021-34574: Update to 2.12.1","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":4.3,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","temporalScore":4.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["CSAFPID-51001","CSAFPID-51002"]}],"title":"CVE-2021-34574"},{"cve":"CVE-2021-34575","cwe":{"id":"CWE-203","name":"Observable Discrepancy"},"notes":[{"category":"description","text":"In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-52002","CSAFPID-52004"],"known_affected":["CSAFPID-51001","CSAFPID-51002"]},"remediations":[{"category":"vendor_fix","details":"CVE-2021-34575: Update to 2.9.0\n\nCVE-2021-34574: Update to 2.12.1","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.5,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.5,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["CSAFPID-51001","CSAFPID-51002"]}],"title":"CVE-2021-34575"}]}