An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://mbconnectline.com/security-advice/ | vendor advisory |
https://cert.vde.com/de-de/advisories/vde-2021-003 | third party advisory |