Mv develops a narrow product portfolio focused on identity and connectivity solutions, with its primary exposure centered on the IDCE and MConnect platforms. The recurring vulnerability profile points toward application input-handling and authentication-management weaknesses, specifically SQL injection, excessive authentication attempt tolerance, and sensitive information disclosure through logging. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mv over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30496HIGH SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's priv | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-23282HIGH SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get ac | Jul 21, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-23283HIGH Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force. | Jul 21, 2021 | 7.5 | 19 | NO | NO |
CVE-2020-23284HIGH Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database | Jul 20, 2021 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mv.
Media articles that mention a CVE ID that affects a product developed by Mv — matched by CVE ID, not by vendor name.