cbcvebase.
CVE-2024-23942
published 2025-03-18

CVE-2024-23942: A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.11%
1.4th percentile
A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.

Affected

4 ranges
VendorProductVersion rangeFixed in
mb_connect_linembconnect24< 2.16.22.16.2
mb_connect_linembnet< 8.2.08.2.0
mb_connect_linembnet.rokey< 8.2.08.2.0
mb_connect_linemymbconnect24< 2.16.22.16.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.