Remote User Enumeration Vulnerability in Unprotected Endpoint
CVE-2025-3092
7.5HIGH
What is CVE-2025-3092?
This vulnerability allows an unauthenticated remote attacker to enumerate valid usernames from an endpoint that lacks adequate protection. Attackers exploiting this flaw can gain insights into valid accounts, potentially setting the stage for further attacks, such as phishing or account compromise. Organizations are encouraged to secure their endpoints and implement measures to prevent user enumeration.
Affected Version(s)
mbCONNECT24 0 < 2.16.5
mymbCONNECT24 0 < 2.18.0
mymbCONNECT24 0 < 2.18.0