PT-2020-13689 · Foxit · Foxit Reader+1

Published

2020-06-04

·

Updated

2020-06-04

·

CVE-2020-13805

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit Reader versions prior to 9.7.2 PhantomPDF versions prior to 9.7.2
Description The issue is related to brute-force attack mishandling due to the CAS service lacking a limit on login failures.
Recommendations For Foxit Reader versions prior to 9.7.2, update to version 9.7.2 or later. For PhantomPDF versions prior to 9.7.2, update to version 9.7.2 or later.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13805

Affected Products

Foxit Reader
Phantompdf