Security Advisory

CVE-2020-12527

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-03-02 21:15:24
Last updated 2024-09-16 20:43:07
Assigner CERTVDE
CVSS score 6.5
State PUBLISHED

Description

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.