PT-2021-11796 · Unknown · Mbconnect24
Published
2021-02-16
·
Updated
2021-02-19
·
CVE-2020-35565
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
mbCONNECT24 versions through 2.6.2
mymbCONNECT24 versions through 2.6.2
Description:
An issue was discovered where the login pages' bruteforce detection is disabled by default.
Recommendations:
For mbCONNECT24 versions through 2.6.2, enable the bruteforce detection on the login pages.
For mymbCONNECT24 versions through 2.6.2, enable the bruteforce detection on the login pages.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mbconnect24