Описание
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
Ссылки
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.0.7-0085 (исключая)
cpe:2.3:a:synology:carddav_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00419
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307
CWE-307
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
EPSS
Процентиль: 61%
0.00419
Низкий
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307
CWE-307