Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21373 | An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected. |
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-010 |
|
Tue, 18 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Mar 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected. | |
| Title | MB connect line: Cloud API access due to a lack of authentication for a critical function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-03-18T13:13:28.924Z
Reserved: 2024-01-24T08:35:23.199Z
Link: CVE-2024-23943
Updated: 2025-03-18T13:12:22.761Z
Status : Deferred
Published: 2025-03-18T11:15:39.090
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-23943
No data.
OpenCVE Enrichment
No data.
EUVD