CVE-2024-45272

HIGH
Published Oct 15, 2024 Modified Nov 21, 2024 CWE-1391

Description

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

Is your site exposed to CVE-2024-45272?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weakness Type (CWE)

CWE-1391 CWE-1391

Affected Products

Vendor Product
helmholz myrex24_v2_virtual_server
helmholz rex_300_firmware
helmholz rex_300
helmholz rex_200_firmware
helmholz rex_200
helmholz rex_250_firmware
helmholz rex_250
mbconnectline mbconnect24
mbconnectline mymbconnect24
mbconnectline mbspider_mdh_905_firmware
mbconnectline mbspider_mdh_905
mbconnectline mbspider_mdh_915_firmware
mbconnectline mbspider_mdh_915
mbconnectline mbspider_mdh_906_firmware
mbconnectline mbspider_mdh_906
mbconnectline mbspider_mdh_916_firmware
mbconnectline mbspider_mdh_916
mbconnectline mbnet_hw1_firmware
mbconnectline mbnet_hw1
mbconnectline mbnet_firmware
mbconnectline mbnet
mbconnectline mbnet.rokey_firmware
mbconnectline mbnet.rokey

References

Frequently Asked Questions

What is CVE-2024-45272? +
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost. It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2024-45272? +
CVE-2024-45272 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-45272? +
CVE-2024-45272 affects products from helmholz, mbconnectline, specifically: mbconnect24, mbnet, mbnet.rokey, mbnet.rokey_firmware, mbnet_firmware, mbnet_hw1, mbnet_hw1_firmware, mbspider_mdh_905, mbspider_mdh_905_firmware, mbspider_mdh_906, mbspider_mdh_906_firmware, mbspider_mdh_915, mbspider_mdh_915_firmware, mbspider_mdh_916, mbspider_mdh_916_firmware, mymbconnect24, myrex24_v2_virtual_server, rex_200, rex_200_firmware, rex_250, rex_250_firmware, rex_300, rex_300_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-45272? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-45272 — free, no signup required.