CVE-2024-45273

HIGH
Published Oct 15, 2024 Modified Nov 21, 2024 CWE-261 CWE-326

Description

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

Is your site exposed to CVE-2024-45273?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.4
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-261 CWE-261
CWE-326 CWE-326

Affected Products

Vendor Product
mbconnectline mbnet.mini_firmware
mbconnectline mbnet.mini
helmholz myrex24_v2_virtual_server
helmholz rex_300_firmware
helmholz rex_300
helmholz rex_200_firmware
helmholz rex_200
helmholz rex_250_firmware
helmholz rex_250
helmholz rex_100_firmware
helmholz rex_100
mbconnectline mbconnect24
mbconnectline mymbconnect24
mbconnectline mbspider_mdh_905_firmware
mbconnectline mbspider_mdh_905
mbconnectline mbspider_mdh_915_firmware
mbconnectline mbspider_mdh_915
mbconnectline mbspider_mdh_906_firmware
mbconnectline mbspider_mdh_906
mbconnectline mbspider_mdh_916_firmware
mbconnectline mbspider_mdh_916
mbconnectline mbnet_hw1_firmware
mbconnectline mbnet_hw1
mbconnectline mbnet_firmware
mbconnectline mbnet
mbconnectline mbnet.rokey_firmware
mbconnectline mbnet.rokey

References

Frequently Asked Questions

What is CVE-2024-45273? +
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. It has a CVSS v3.1 base score of 8.4 (HIGH).
How severe is CVE-2024-45273? +
CVE-2024-45273 has a CVSS v3.1 score of 8.4 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-45273? +
CVE-2024-45273 affects products from helmholz, mbconnectline, specifically: mbconnect24, mbnet, mbnet.mini, mbnet.mini_firmware, mbnet.rokey, mbnet.rokey_firmware, mbnet_firmware, mbnet_hw1, mbnet_hw1_firmware, mbspider_mdh_905, mbspider_mdh_905_firmware, mbspider_mdh_906, mbspider_mdh_906_firmware, mbspider_mdh_915, mbspider_mdh_915_firmware, mbspider_mdh_916, mbspider_mdh_916_firmware, mymbconnect24, myrex24_v2_virtual_server, rex_100, rex_100_firmware, rex_200, rex_200_firmware, rex_250, rex_250_firmware, rex_300, rex_300_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-45273? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-45273 — free, no signup required.