Description

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

Severity (CVSS)

Base score8.6
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-425 — CWE-425 Direct Request ('Forced Browsing')

Affected products

VendorProductVersions
MB connect linembCONNECT240.0.0 to <2.20.2
MB connect linemymbCONNECT240.0.0 to <2.20.2
MB connect linembCONNECT242.20.1
MB connect linemymbCONNECT242.20.1

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 23 Jun 2026 10:05 UTC.