← Vulnerability feed

Vulnerability record · CVE-2023-0985 · published 6 June 2023

CVE-2023-0985: Mbconnectline mbconnect24 insecure direct object reference vulnerability

Mbconnectline · Mbconnect24

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.

8.8 CVSS 3.1 High EPSS 0.79% · top 45.4% CWE-639 · Insecure direct object reference
8.8CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert.vde.com/en/advisories/VDE-2023-002/ MitigationThird Party Advisory
https://cert.vde.com/en/advisories/VDE-2023-002/ MitigationThird Party Advisory

Track CVE-2023-0985 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-35565Mbconnectline mbconnect24 improper restriction of authentication attempts vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.EPSS 1.1%9.8CVE-2020-10383Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remo…EPSS 1.8%9.1CVE-2026-33615Mbconnectline mbconnect24 sql injection vulnerabilityAn unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …EPSS 0.59%8.8CVE-2026-33613Mbconnectline mbconnect24 os command injection vulnerabilityDue to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr…EPSS 0.69%8.8CVE-2020-10382Mbconnectline mbconnect24 vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote…EPSS 1.9%7.8CVE-2024-45273Mbconnectline mbnet.mini firmware inadequate encryption strength vulnerabilityAn unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encrypt…EPSS 0.09%7.8CVE-2020-35567Mbconnectline mbconnect24 hard-coded credentials vulnerabilityAn issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but …EPSS 0.25%7.8CVE-2020-10384Mbconnectline mbconnect24 improper privilege management vulnerabilityAn issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escal…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2023-0985), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.