PT-2022-4232 · Octoprint · Octoprint
Published
2022-08-15
·
Updated
2022-08-16
·
CVE-2022-2822
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OctoPrint versions 1.7.3 and prior
Description
The issue is related to insufficient restriction of authentication attempts, allowing a remote attacker to bypass security restrictions using a brute force attack. This can enable an attacker to freely brute force
username and password, taking over any account, including user and administrative accounts. The severity of this issue is limited by OctoPrint normally running in a restricted LAN.Recommendations
For OctoPrint versions 1.7.3 and prior, consider updating to a version that includes rate limiting on the login page, such as versions from the
devel and maintenance branches of the repository, which limit the rate of failed login attempts. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Octoprint