Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40982
HistoryJun 22, 2023 - 7:21 a.m.

Brute Force Attack

2023-06-2207:21:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
froxlor
vulnerability
brute force
2fa
unauthorized actions
software

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.8%

froxlor/froxlor is vulnerable to Brute Force Attacks. The vulnerability exists because it does not limit 2FA attempts, which allows an attacker to brute force the user credentials and perform unauthorized actions.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.8%

Related for VERACODE:40982