{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"There is a vulnerability in mbCONNECT24/mymbCONNECT24 that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.","title":"Summary"},{"category":"description","text":"CVE-2026-10521 allows an authenticated remote attacker to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.","title":"Impact"},{"category":"description","text":"Update the mbCONNECT24/mymbCONNECT24 instance to version 2.20.2.\n","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"external","summary":"Product security incident reports","url":"https://mbconnectline.com/security-advice"},{"category":"self","summary":"Security Incident Management SIM#2026-04 - PDF","url":"https://advisories.mbconnectline.com/pdf/SIM2026-04.pdf"},{"category":"external","summary":"CERT@VDE Security Advisories for MB connect line","url":"https://certvde.com/en/advisories/vendor/mbconnectline"},{"category":"self","summary":"VDE-2026-068: MB connect line: Authenticated unintended access to critical program parameters in mbCONNECT24/mymbCONNECT24 - HTML","url":"https://certvde.com/en/advisories/VDE-2026-068"},{"category":"self","summary":"VDE-2026-068: MB connect line: Authenticated unintended access to critical program parameters in mbCONNECT24/mymbCONNECT24 - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-068.json"}],"title":"MB connect line: Authenticated unintended access to critical program parameters in mbCONNECT24/mymbCONNECT24","tracking":{"aliases":["VDE-2026-068","SIM#2026-04"],"current_release_date":"2026-06-23T11:00:00.000Z","generator":{"date":"2026-06-18T09:38:03.021Z","engine":{"name":"Secvisogram","version":"2.5.44"}},"id":"VDE-2026-068","initial_release_date":"2026-06-23T11:00:00.000Z","revision_history":[{"date":"2026-06-23T11:00:00.000Z","number":"1.0.0","summary":"Initial revision."}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_family","name":"mbCONNECT24","product":{"name":"MB connect line mbCONNECT24","product_id":"CSAFPID-11001","product_identification_helper":{"cpe":"cpe:2.3:h:mb_connect_line:mbCONNECT24:*:*:*:*:*:*:*:*"}}},{"category":"product_name","name":"mymbCONNECT24","product":{"name":"MB connect line mymbCONNECT24","product_id":"CSAFPID-11002","product_identification_helper":{"cpe":"cpe:2.3:h:mb_connect_line:mymbCONNECT24:*:*:*:*:*:*:*:*"}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"vers:semver/<2.20.2","product":{"name":"Firmware <2.20.2","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"2.20.2","product":{"name":"Firmware 2.20.2","product_id":"CSAFPID-21002","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24_firmware:2.20.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"2.20.1","product":{"name":"Firmware 2.20.1","product_id":"CSAFPID-21003","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24_firmware:2.20.1:*:*:*:*:*:*:*"}}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"],"summary":"Affected products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-31005","CSAFPID-31006"],"summary":"Fixed products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware <2.20.2 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware <2.20.2 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.20.1 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31003","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24:2.20.1:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.20.1 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31004","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.1:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21003","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.20.2 installed on MB connect line mbCONNECT24","product_id":"CSAFPID-31005","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mbconnect24:2.20.2:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11001"},{"category":"installed_on","full_product_name":{"name":"Firmware 2.20.2 installed on MB connect line mymbCONNECT24","product_id":"CSAFPID-31006","product_identification_helper":{"cpe":"cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.2:*:*:*:*:*:*:*"}},"product_reference":"CSAFPID-21002","relates_to_product_reference":"CSAFPID-11002"}]},"vulnerabilities":[{"cve":"CVE-2026-10521","cwe":{"id":"CWE-425","name":"Direct Request ('Forced Browsing')"},"notes":[{"audience":"all","category":"description","text":"An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.","title":"CVE Description"}],"product_status":{"fixed":["CSAFPID-31005","CSAFPID-31006"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]},"references":[{"category":"external","summary":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 8.6 / High","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Update the mbCONNECT24/mymbCONNECT24 instance to version 2.20.2.","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":7.2,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","temporalScore":7.2,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004"]}],"title":"Authenticated unintended access to critical program parameters"}]}