CVE-2024-45273: Helmholz MYREX24 v2 Virtual Server
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Affected products
- Helmholz MYREX24 v2 Virtual Server: before 2.16.3 (fixed in 2.16.3)
- Helmholz Rex 100 Firmware: before 2.3.1 (fixed in 2.3.1)
- Helmholz Rex 200 Firmware: before 8.2.1 (fixed in 8.2.1)
- Helmholz Rex 250 Firmware: before 8.2.1 (fixed in 8.2.1)
- Helmholz Rex 300 Firmware: up to and including 5.1.11
- Mbconnectline MBCONNECT24: before 2.16.3 (fixed in 2.16.3)
- Mbconnectline Mbnet.mini Firmware: before 2.3.1 (fixed in 2.3.1)
- Mbconnectline Mbnet.rokey Firmware: before 8.2.1 (fixed in 8.2.1)
- Mbconnectline Mbnet Firmware: before 8.2.1 (fixed in 8.2.1)
- Mbconnectline Mbnet HW1 Firmware: up to and including 5.1.11
- Mbconnectline Mbspider Mdh 905 Firmware: up to and including 2.6.5
- Mbconnectline Mbspider Mdh 906 Firmware: up to and including 2.6.5
- Mbconnectline Mbspider Mdh 915 Firmware: up to and including 2.6.5
- Mbconnectline Mbspider Mdh 916 Firmware: up to and including 2.6.5
- Mbconnectline MYMBCONNECT24: before 2.16.3 (fixed in 2.16.3)
Published 2024-10-15. Last modified 2026-06-17.