Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22pf-6rh7-89gj

Опубликовано: 26 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

EPSS

Процентиль: 22%
0.00071
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.3
nvd
10 месяцев назад

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

EPSS

Процентиль: 22%
0.00071
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307