Discover the CVE-2020-35559 vulnerability in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24, allowing authenticated attackers to exhaust all available IPs, hindering new device and user creation. Learn mitigation steps here.
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.
Understanding CVE-2020-35559
This CVE identifies a vulnerability in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 that can be exploited by authenticated attackers to exhaust all available IPs of an account.
What is CVE-2020-35559?
The CVE-2020-35559 vulnerability in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 allows authenticated attackers to consume all IPs in an account, preventing the creation of new devices and users.
The Impact of CVE-2020-35559
The exploitation of this vulnerability can lead to a denial of service condition, hindering the normal operation of the affected systems.
Technical Details of CVE-2020-35559
This section provides more in-depth technical information about the CVE-2020-35559 vulnerability.
Vulnerability Description
The vulnerability arises from an unused function in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24, enabling authenticated attackers to exhaust all available IPs within an account.
Affected Systems and Versions
Exploitation Mechanism
The attacker needs to be authenticated to exploit this vulnerability, allowing them to consume all available IPs within the account.
Mitigation and Prevention
Protecting systems from CVE-2020-35559 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure that the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 systems are updated to versions that address the CVE-2020-35559 vulnerability.