{"document":{"acknowledgments":[{"organization":"CERTVDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"SySS GmBH","summary":"reporting","urls":["https://www.syss.de"]},{"organization":"Helmholz","summary":"reporting","urls":["https://www.helmholz.de"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"An issue was discovered in the mymbCONNECT24 and mbCONNECT24 software in all versions through V2.11.2.","title":"Summary"},{"category":"description","text":"A remote, unauthenticated attacker can enumerate valid users with a timing attack against the webserver.","title":"Impact"},{"category":"description","text":"Update to Version 2.12.1","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"self","summary":"VDE-2022-011: MB connect line: Unauthenticated user enumeration in mbCONNECT24 and mymbCONNECT24 - HTML","url":"https://certvde.com/de/advisories/VDE-2022-011/"},{"category":"external","summary":"CERT@VDE Security Advisories for ","url":"https://certvde.com/en/advisories/vendor/mbconnectline/"},{"category":"self","summary":"VDE-2022-011: MB connect line: Unauthenticated user enumeration in mbCONNECT24 and mymbCONNECT24 - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-011.json"}],"title":"MB connect line: Unauthenticated user enumeration in mbCONNECT24 and mymbCONNECT24","tracking":{"aliases":["VDE-2022-011"],"current_release_date":"2022-09-07T12:50:00.000Z","generator":{"date":"2025-03-21T11:47:01.298Z","engine":{"name":"Secvisogram","version":"2.5.21"}},"id":"VDE-2022-011","initial_release_date":"2022-09-07T12:50:00.000Z","revision_history":[{"date":"2022-09-07T12:50:00.000Z","number":"1","summary":"initial revision"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"mbCONNECT24","product":{"name":"mbCONNECT24","product_id":"CSAFPID-11001"}},{"category":"product_name","name":"mymbCONNECT24","product":{"name":"mymbCONNECT24","product_id":"CSAFPID-11002"}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<=2.11.2","product":{"name":"Firmware <=2.11.2","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"2.12.1","product":{"name":"Firmware 2.12.1","product_id":"CSAFPID-22001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line GmbH"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002"],"summary":"affected products"},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002"],"summary":"fixed products"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <=2.11.2 installed on mbCONNECT24","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.12.1 installed on mbCONNECT24","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <=2.11.2 installed on mymbCONNECT24","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.12.1 installed on mymbCONNECT24","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"}]},"vulnerabilities":[{"cve":"CVE-2022-22520","cwe":{"id":"CWE-204","name":"Observable Response Discrepancy"},"notes":[{"category":"summary","text":"A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2."}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002"],"known_affected":["CSAFPID-31001","CSAFPID-31002"]},"remediations":[{"category":"vendor_fix","details":"Update to Version 2.12.1","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":5.3,"environmentalSeverity":"MEDIUM","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":5.3,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002"]}],"title":"CVE-2022-22520"}]}