PT-2023-32820 · M Files · M-Files Server

Published

2023-12-20

·

Updated

2026-02-23

·

CVE-2023-6912

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 23.12.13205.0
Description The issue is related to a lack of protection against brute force attacks, allowing an attacker to make unlimited authentication attempts. This could potentially compromise targeted M-Files user accounts by guessing passwords.
Recommendations For versions prior to 23.12.13205.0, update to version 23.12.13205.0 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication security measures, such as rate limiting or account lockout policies, to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2023-6912

Affected Products

M-Files Server