PT-2020-3651 · Spacelynk · Spacelynk+1

Published

2020-08-11

·

Updated

2023-05-10

·

CVE-2020-7525

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions spaceLYnk (affected versions not specified) Wiser for KNX (formerly homeLYnk) (affected versions not specified)
Description The issue is related to an improper restriction of excessive authentication attempts, which could allow an attacker to guess a password using brute force. This vulnerability may enable a remote attacker to bypass the authentication procedure.
Recommendations For spaceLYnk, consider implementing restrictions on authentication attempts to prevent brute force attacks until a fix is available. For Wiser for KNX (formerly homeLYnk), restrict access to the authentication mechanism to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2020-03999
CVE-2020-7525

Affected Products

Wiser For Knx
Spacelynk