CVE-2024-45274

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
15/10/2024
Last modified:
17/10/2024

Description

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mbconnectline:mbnet.mini_firmware:*:*:*:*:*:*:*:* 2.3.1 (excluding)
cpe:2.3:h:mbconnectline:mbnet.mini:-:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:rex_100_firmware:*:*:*:*:*:*:*:* 2.3.1 (excluding)
cpe:2.3:h:helmholz:rex_100:-:*:*:*:*:*:*:*