LiveActive security incident?Get immediate response
CVE Record

CVE-2020-12528: An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V...

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in the account he should not have access to.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A logged-in user could terminate web2go sessions belonging to accounts they should not control. This does not expose data or change systems directly, but it can disrupt remote access availability for affected MB connect line platforms.

Executive priority

Handle as a moderate operational availability issue. It is most urgent where remote access continuity matters, where many users have accounts, or where session disruption could affect industrial support workflows.

Technical view

CVE-2020-12528 is an improper access validation issue in mymbCONNECT24 and mbCONNECT24 through V2.6.2. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, meaning a network-accessible authenticated user can cause high availability impact.

Likely exposure

Exposure appears limited to organizations running MB connect line mymbCONNECT24 or mbCONNECT24 versions through V2.6.2, especially where multiple authenticated users share the platform and web2go sessions are operationally important.

Exploitation context

The source bundle does not cite public exploitation, and the CVE is not listed as KEV. Treat it as a denial-of-service risk from authenticated users, not as confirmed active exploitation.

Researcher notes

The available evidence identifies improper access validation and authenticated session-kill impact, but does not include detailed root cause, fixed version, or exploit observations. Avoid assuming broader account takeover, confidentiality impact, or unauthenticated reachability.

Mitigation direction

  • Inventory mymbCONNECT24 and mbCONNECT24 deployments and versions.
  • Review the MB connect line or VDE advisory for supported remediation.
  • Restrict platform access to users with a clear operational need.
  • Monitor for unexpected web2go session termination events.
  • Prioritize controls for shared or multi-tenant accounts.

Validation and detection

  • Confirm whether any deployment runs version V2.6.2 or earlier.
  • Verify who can authenticate to the affected platform.
  • Review logs for unexplained web2go session kills.
  • Check whether vendor remediation has been applied.
  • Document any compensating access restrictions.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-269: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-12528 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.5Medium
CVSS 3.1 vector shape for CVE-2020-12528Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
MB connect linemymbCONNECT242.6.2Listed
MB connect linembCONNECT242.6.2Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-269 · source CWE mapping

Improper Privilege Management

Improper Privilege Management represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.