PT-2022-4232 · Octoprint · Octoprint

Published

2022-08-15

·

Updated

2022-08-16

·

CVE-2022-2822

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions OctoPrint versions 1.7.3 and prior
Description The issue is related to insufficient restriction of authentication attempts, allowing a remote attacker to bypass security restrictions using a brute force attack. This can enable an attacker to freely brute force username and password, taking over any account, including user and administrative accounts. The severity of this issue is limited by OctoPrint normally running in a restricted LAN.
Recommendations For OctoPrint versions 1.7.3 and prior, consider updating to a version that includes rate limiting on the login page, such as versions from the devel and maintenance branches of the repository, which limit the rate of failed login attempts. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05080
CVE-2022-2822
GHSA-5W5X-Q9P5-9QG3

Affected Products

Octoprint