Server-Side Request Forgery Vulnerability in MB connect line Products
CVE-2020-12529
5.8MEDIUM
What is CVE-2020-12529?
A server-side request forgery (SSRF) vulnerability has been identified in MB connect line's mymbCONNECT24 and mbCONNECT24 software. This issue exists in all versions up to V2.6.2, allowing an attacker to exploit the LDAP access check. By leveraging this vulnerability, an attacker can perform unauthorized port scanning on the server, potentially exposing sensitive information about open ports and services running on the machine.
Affected Version(s)
mbCONNECT24 2.6.2
mymbCONNECT24 2.6.2
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
OTORIO reported the vulnerabilities to MB connect line. CERT@VDE coordinated.