Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x9g-pvv2-c542

Опубликовано: 11 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.

EPSS

Процентиль: 69%
0.00614
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.

EPSS

Процентиль: 69%
0.00614
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-307