{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"names":["Moritz Abrell","Christian Zäske"],"organization":"SySS GmbH","summary":"reporting","urls":["https://www.syss.de"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24 that could allow unauthenticated RCE or SQLi.","title":"Summary"},{"category":"description","text":"CVE-2026-32968 allows unauthenticated RCE resulting in full system compromise impacting confidentiality, integrity, and availability, while CVE-2026-32969 allows unauthenticated SQLi resulting in arbitrary read access to the complete database.","title":"Impact"},{"category":"description","text":"Update the mbCONNECT24/mymbCONNECT24 instance to version 2.19.4.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"external","summary":"Product security incident reports","url":"https://mbconnectline.com/security-advice"},{"category":"self","summary":"Security Incident Management SIM#2026-02 - PDF","url":"https://advisories.mbconnectline.com/pdf/SIM2026-02.pdf"},{"category":"external","summary":"CERT@VDE Security Advisories for MB connect line","url":"https://certvde.com/en/advisories/vendor/mbconnectline"},{"category":"self","summary":"VDE-2026-024: MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24 - HTML","url":"https://certvde.com/en/advisories/VDE-2026-024"},{"category":"self","summary":"VDE-2026-024: MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24 - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-024.json"}],"title":"MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24","tracking":{"aliases":["VDE-2026-024","SIM#2026-02"],"current_release_date":"2026-03-23T12:00:00.000Z","generator":{"date":"2026-03-23T10:36:54.833Z","engine":{"name":"Secvisogram","version":"2.5.44"}},"id":"VDE-2026-024","initial_release_date":"2026-03-23T12:00:00.000Z","revision_history":[{"date":"2026-03-23T12:00:00.000Z","number":"1.0.0","summary":"Initial revision."}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_family","name":"mbCONNECT24","product":{"name":"MB connect line mbCONNECT24","product_id":"CSAFPID-11001","product_identification_helper":{"cpe":"cpe:2.3:h:mb_connect_line:mbCONNECT24:*:*:*:*:*:*:*:*"}}},{"category":"product_name","name":"mymbCONNECT24","product":{"name":"MB connect line mymbCONNECT24","product_id":"CSAFPID-11002","product_identification_helper":{"cpe":"cpe:2.3:h:mb_connect_line:mymbCONNECT24:*:*:*:*:*:*:*:*"}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"vers:semver/<=2.19.3","product":{"name":"Firmware <=2.19.3","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"2.19.4","product":{"name":"Firmware 2.19.4","product_id":"CSAFPID-21002","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24_firmware:2.19.4:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"2.19.3","product":{"name":"Firmware 2.19.3","product_id":"CSAFPID-21003","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24_firmware:2.19.3:*:*:*:*:*:*:*"}}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-31005","CSAFPID-31006"],"summary":"Fixed products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <=2.19.3 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <=2.19.3 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.19.3 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.19.3 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.19.4 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31005"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.19.4 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31006"},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"}]},"vulnerabilities":[{"cve":"CVE-2026-32968","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"audience":"all","category":"description","text":"Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.","title":"CVE Description"}],"product_status":{"fixed":["CSAFPID-31005","CSAFPID-31006"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"vendor_fix","details":"Update the mbCONNECT24/mymbCONNECT24 instance to version 2.19.4.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.8,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.8,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]}],"title":"Unauthenticated RCE in com_mb24sysapi"},{"cve":"CVE-2026-32969","cwe":{"id":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"},"notes":[{"audience":"all","category":"description","text":"An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.","title":"CVE Description"}],"product_status":{"fixed":["CSAFPID-31005","CSAFPID-31006"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]},"remediations":[{"category":"vendor_fix","details":"Update the mbCONNECT24/mymbCONNECT24 instance to version 2.19.4.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.5,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.5,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]}],"title":"Pre-Auth Blind SQLi in userinfo Endpoint"}]}