PT-2021-20078 · Fimer · Fimer Aurora Vision

Published

2021-11-03

·

Updated

2021-11-05

·

CVE-2021-33209

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fimer Aurora Vision versions prior to 2.97.10
Description An issue was discovered where the response to a failed login attempt discloses whether the username or password is wrong, helping an attacker to enumerate usernames. This can make a brute-force attack easier.
Recommendations For versions prior to 2.97.10, update to version 2.97.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the login functionality to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33209

Affected Products

Fimer Aurora Vision