CVE-2024-45273
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-261
- Published
- 2024-10-15
- Last modified
- 2026-03-13
Affected products
- MB connect line mbNET.mini
- MB connect line mbNET/mbNET.rokey
- MB connect line mbNET HW1
- MB connect line mbSPIDER
- MB connect line mbCONNECT24
- MB connect line mymbCONNECT24
- Helmholz REX100
- Helmholz REX200/250
Weakness type
Related vulnerabilities
- CVE-2020-10275 — RVD#2565: Weak token generation for the REST API.
- CVE-2024-45394 — Secret encryption vulnerable to brute-force attacks
- CVE-2021-21507 — Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2024-7407 — Weak password encoding in Streamsoft Prestiż
- CVE-2024-8455 — PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords
- CVE-2022-45099 — Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged lo
- CVE-2023-0525 — Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000