cbcvebase.
CVE-2024-23943
published 2025-03-18

CVE-2024-23943: An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices…

PriorityP267critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.56%
42.4th percentile
An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected.

Affected

4 ranges
VendorProductVersion rangeFixed in
mb_connect_linembconnect24< 2.16.22.16.2
mb_connect_linembnet< 8.2.08.2.0
mb_connect_linembnet.rokey< 8.2.08.2.0
mb_connect_linemymbconnect24< 2.16.22.16.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.