CVE-2024-23943 describes a critical authentication bypass vulnerability in the data24 service bundled with mbCONNECT24 and mymbCONNECT24 products. An unauthenticated remote attacker can exploit this flaw to gain full access to the cloud API due to a lack of authentication for a critical function. With a CVSS score of 9.1 (CRITICAL), this vulnerability allows for complete compromise of confidentiality and integrity (C:H, I:H) without user interaction or prior privileges, though availability is not impacted. While there is no known active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MB Connect Line | MbCONNECT24 | >= 0, < 2.16.2CNA affecteddefault unaffected | |
| MB Connect Line | MbNET | >= 0, < 8.2.0CNA affecteddefault unaffected | |
| MB Connect Line | MbNET.Rokey | >= 0, < 8.2.0CNA affecteddefault unaffected | |
| MB Connect Line | MymbCONNECT24 | >= 0, < 2.16.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.