PT-2022-23836 · Plextrac · Plextrac
Konrad Haase
·
Published
2022-09-08
·
Updated
2022-09-13
·
CVE-2022-37144
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PlexTrac platform versions prior to 1.17.0
Description
The issue allows an unauthenticated remote attacker with a valid username and password to bruteforce their way past MFA protections and login as the targeted user due to the lack of restriction on excessive MFA TOTP submission attempts.
Recommendations
For versions prior to 1.17.0, update to API version 1.17.0 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to restrict excessive login attempts.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plextrac