Описание
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
Ссылки
- Vendor Advisory
- Issue TrackingPatchVendor Advisory
- Vendor Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:netgate:pfsense_plus:22.05.1:*:*:*:*:*:*:*
cpe:2.3:a:pfsense:pfsense:2.6.0:*:*:*:community:*:*:*
EPSS
Процентиль: 85%
0.02577
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-307
CWE-307
Связанные уязвимости
CVSS3: 9.8
github
почти 3 года назад
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
EPSS
Процентиль: 85%
0.02577
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-307
CWE-307