PT-2022-21437 · Rdiffweb · Rdiffweb

Published

2022-10-06

·

Updated

2022-10-10

·

CVE-2022-3273

CVSS v3.1

3.6

Low

VectorAV:P/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.5.0a4
Description The issue concerns the allocation of resources without limits or throttling, which can be exploited for brute force attacks to guess passwords. There is no rate limit to prevent attackers from attempting multiple incorrect password attempts. It is estimated that this could potentially affect a significant number of devices worldwide, although the exact number is not specified.
Recommendations For versions prior to 2.5.0a4, update to version 2.5.0a4 or later to implement a limit on the number of incorrect password attempts, preventing brute force attacks.

Exploit

Fix

Allocation of Resources Without Limits

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3273
GHSA-9G3V-V24Q-JJ5P
PYSEC-2022-43156

Affected Products

Rdiffweb