PT-2022-23836 · Plextrac · Plextrac

Konrad Haase

·

Published

2022-09-08

·

Updated

2022-09-13

·

CVE-2022-37144

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PlexTrac platform versions prior to 1.17.0
Description The issue allows an unauthenticated remote attacker with a valid username and password to bruteforce their way past MFA protections and login as the targeted user due to the lack of restriction on excessive MFA TOTP submission attempts.
Recommendations For versions prior to 1.17.0, update to API version 1.17.0 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to restrict excessive login attempts.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2022-37144

Affected Products

Plextrac