CVE-2021-34580
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-204
- Published
- 2021-10-27
- Last modified
- 2026-03-13
Affected products
- MB connect line mymbCONNECT24
- MB connect line mbCONNECT24
Weakness type
Related vulnerabilities
- CVE-2026-33419 — MinIO: LDAP login brute-force via user enumeration and missing rate limit
- CVE-2025-5485 — SinoTrack GPS Receiver Weak Authentication
- CVE-2018-25350 — userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
- CVE-2026-6207 — Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting. T
- CVE-2026-60007 — In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
- CVE-2026-15747 — Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
- CVE-2025-46390 — CWE-204: Observable Response Discrepancy
- CVE-2025-3092 — MB connect line: Observable response discrepancy in mbCONNECT24/mymbCONNECT24