Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19010 | An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password. |
Tue, 24 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Jun 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password. | |
| Title | MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24 | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-06-24T13:56:13.121Z
Reserved: 2025-04-01T13:41:22.429Z
Link: CVE-2025-3091
Updated: 2025-06-24T13:56:08.753Z
Status : Deferred
Published: 2025-06-24T09:15:25.190
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-3091
No data.
OpenCVE Enrichment
No data.
EUVD