PT-2020-14042 · Openclinic · Openclinic Ga

Brian D. Hysell

·

Published

2020-07-20

·

Updated

2021-11-04

·

CVE-2020-14494

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClinic GA versions 5.09.02 through 5.89.05b
Description The issue concerns an authentication mechanism within the system that lacks sufficient complexity, making it vulnerable to brute force attacks. This could allow unauthorized users to access the system after a limited number of attempts.
Recommendations For OpenClinic GA versions 5.09.02 through 5.89.05b, consider implementing additional security measures to enhance the authentication mechanism, such as increasing the complexity of passwords or introducing a rate-limiting feature to mitigate brute force attacks. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14494

Affected Products

Openclinic Ga