CVE-2020-12528
Estado: ModificadaAlta (7.7)—
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- Puntuación base: 7.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-269
- CWE-269
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-12528",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "MB connect line",
"product": "mymbCONNECT24",
"versions": [
{
"status": "affected",
"version": "2.6.2",
"versionType": "custom",
"lessThanOrEqual": "2.6.2"
}
]
},
{
"vendor": "MB connect line",
"product": "mbCONNECT24",
"versions": [
{
"status": "affected",
"version": "2.6.2",
"versionType": "custom",
"lessThanOrEqual": "2.6.2"
}
]
}
]
}
],
"published": "2021-03-02T22:15:12.480",
"references": [
{
"url": "https://cert.vde.com/de-de/advisories/vde-2021-003",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/de-de/advisories/vde-2021-003",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to."
},
{
"lang": "es",
"value": "Se detectó un problema en el software MB connect line mymbCONNECT24 y mbCONNECT24 en todas las versiones hasta la V2.6.2. El uso inapropiado de la comprobación de acceso permite que un usuario que haya iniciado sesión elimine las sesiones de web2go en la cuenta a la que no debería tener acceso"
}
],
"lastModified": "2026-06-17T02:51:58.843",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD64D150-3FCD-4973-88EB-FDCBBC39BB4C",
"versionEndIncluding": "2.6.2"
},
{
"criteria": "cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDA4DEB0-F344-4B04-8BFD-1D405D0CED23",
"versionEndIncluding": "2.6.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "info@cert.vde.com"
}