Описание
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
Ссылки
- Broken Link
- Vendor Advisory
- US Government Resource
- Not Applicable
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00083
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-204
Связанные уязвимости
CVSS3: 5.3
github
8 месяцев назад
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
EPSS
Процентиль: 24%
0.00083
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-204