Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29084

Опубликовано: 02 июн. 2022
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:unity_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.2.0.0.5.173 (исключая)
cpe:2.3:a:dell:unity_xt_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.2.0.0.5.173 (исключая)
cpe:2.3:a:dell:unityvsa_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.2.0.0.5.173 (исключая)

EPSS

Процентиль: 80%
0.01427
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-307
CWE-307

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

EPSS

Процентиль: 80%
0.01427
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-307
CWE-307