PT-2002-1504 · Oblix · Oblix Netpoint
Publicado
2002-06-11
·
Atualizado
2008-09-05
·
CVE-2002-0453
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oblix NetPoint versions 5.2 and earlier
Description
The account lockout feature in the affected software only locks out users once for the specified lockout period. This makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again.
Recommendations
For Oblix NetPoint versions 5.2 and earlier, consider implementing additional security measures to prevent brute force password guessing, such as increasing the lockout period or limiting the number of login attempts. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oblix Netpoint