PT-2020-12750 · Ixsystems · Freenas

Published

2020-04-08

·

Updated

2021-07-21

·

CVE-2020-11650

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iXsystems FreeNAS versions 11.2 through 11.2-u7 iXsystems FreeNAS versions 11.3 through 11.3-U0
Description The issue allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.
Recommendations For iXsystems FreeNAS versions 11.2 through 11.2-u7, update to version 11.2-u8 or later. For iXsystems FreeNAS versions 11.3 through 11.3-U0, update to version 11.3-U1 or later.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11650

Affected Products

Freenas