PT-2022-21692 · Wijungle · Wijungle Ngfw

Harshit Rajpal

·

Published

2022-10-12

·

Updated

2025-05-16

·

CVE-2022-33106

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WiJungle NGFW Version U250
Description The issue allows an attacker to perform a No Rate Limit attack, enabling them to brute force the admin password, which can lead to Account Take Over.
Recommendations For WiJungle NGFW Version U250, consider temporarily restricting access to the admin login functionality until a patch is available. As a mitigation measure, restrict access to the admin interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2022-33106

Affected Products

Wijungle Ngfw