CVE-2024-23942 Details
Description
A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.
A vulnerability exists in MB connect line's mbCONNECT24 and mymbCONNECT24 services, affecting versions prior to 2.16.2. A local user may discover an unencrypted configuration file containing sensitive data on the client workstation. This exposure allows an attacker to impersonate the device or disrupt its connection to the cloud portal, causing a denial-of-service.
Users can update to the latest version, 2.16.2, to address this vulnerability. For mbNET and mbNET.rokey devices with firmware versions 8.0.0 to 8.1.3, the update should be to version 8.2.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 18, 2025CISA-ADP
Assessed Mar 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-010 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MB connect line mbCONNECT24 | < 2.16.2 (semver) |
CPE
Remediation
| |
| MB connect line mbNET | All versions |
CPE
Remediation
| |
| MB connect line mbNET.rokey | All versions |
CPE
Remediation
| |
| MB connect line mymbCONNECT24 | < 2.16.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | CVE Modified | [email protected] |
| Mar 18, 2025 | New CVE Received | [email protected] |
Volerion