High severity7.5NVD Advisory· Published Oct 27, 2021· Updated Jun 17, 2026
CVE-2021-34580
CVE-2021-34580
Description
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*range: <=2.9.0
- cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*range: <=2.9.0
- (no CPE)range: <=2.9.0
- (no CPE)range: 2.9.0
- (no CPE)range: 2.9.0
Patches
Vulnerability mechanics
References
1- cert.vde.com/en/advisories/VDE-2021-037/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.