Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhf7-g3jp-w7f7

Опубликовано: 23 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8

Описание

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

EPSS

Процентиль: 19%
0.0006
Низкий

8.8 High

CVSS4

Дефекты

CWE-307

Связанные уязвимости

nvd
8 месяцев назад

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

EPSS

Процентиль: 19%
0.0006
Низкий

8.8 High

CVSS4

Дефекты

CWE-307