CVE-2024-45273

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 15, 2024
Updated: Nov 21, 2024
CWE ID 326
CWE ID 261

Summary

CVE-2024-45273 is a newly identified vulnerability that allows an unauthenticated local attacker to decrypt the device's configuration file. This weakness in the encryption implementation puts the device at risk of compromise, potentially giving the attacker unauthorized access and control. The specifics of the encryption method and how it can be exploited have not been disclosed, but affected devices are urged to apply patches or updates as soon as they become available to mitigate the risk. This vulnerability underscores the importance of robust encryption and timely software updates to protect against unauthorized access and potential compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MB NET
  • mbConnect24
  • mymbCONNECT24
  • Mbconnectline Mbconnect24
  • Mbconnectline Mymbconnect24

Affected Vendors

  • Multibanco
  • MB Connect Line