PT-2020-3651 · Spacelynk · Spacelynk+1
Published
2020-08-11
·
Updated
2023-05-10
·
CVE-2020-7525
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
spaceLYnk (affected versions not specified)
Wiser for KNX (formerly homeLYnk) (affected versions not specified)
Description
The issue is related to an improper restriction of excessive authentication attempts, which could allow an attacker to guess a password using brute force. This vulnerability may enable a remote attacker to bypass the authentication procedure.
Recommendations
For spaceLYnk, consider implementing restrictions on authentication attempts to prevent brute force attacks until a fix is available.
For Wiser for KNX (formerly homeLYnk), restrict access to the authentication mechanism to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wiser For Knx
Spacelynk