An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://mbconnectline.com/security-advice/ | vendor advisory |
https://cert.vde.com/de-de/advisories/vde-2021-003 | third party advisory |