Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8g3-m2c8-8x9w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).

In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).

EPSS

Процентиль: 56%
0.00343
Низкий

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).

EPSS

Процентиль: 56%
0.00343
Низкий

Дефекты

CWE-307