PT-2020-14042 · Openclinic · Openclinic Ga
Brian D. Hysell
·
Published
2020-07-20
·
Updated
2021-11-04
·
CVE-2020-14494
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClinic GA versions 5.09.02 through 5.89.05b
Description
The issue concerns an authentication mechanism within the system that lacks sufficient complexity, making it vulnerable to brute force attacks. This could allow unauthorized users to access the system after a limited number of attempts.
Recommendations
For OpenClinic GA versions 5.09.02 through 5.89.05b, consider implementing additional security measures to enhance the authentication mechanism, such as increasing the complexity of passwords or introducing a rate-limiting feature to mitigate brute force attacks. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Improper Restriction of Excessive Authentication Attempts
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclinic Ga