PT-2002-1504 · Oblix · Oblix Netpoint

Publicado

2002-06-11

·

Atualizado

2008-09-05

·

CVE-2002-0453

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oblix NetPoint versions 5.2 and earlier
Description The account lockout feature in the affected software only locks out users once for the specified lockout period. This makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again.
Recommendations For Oblix NetPoint versions 5.2 and earlier, consider implementing additional security measures to prevent brute force password guessing, such as increasing the lockout period or limiting the number of login attempts. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0453

Produtos afetados

Oblix Netpoint