PT-2023-5705 · Weintek · Weintek Weincloud
Hank Chen
·
Published
2023-07-18
·
Updated
2023-07-26
·
CVE-2023-32657
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weintek Weincloud version 0.13.6
Description
The issue is related to insufficient restriction of authentication attempts, allowing a remote attacker to perform a brute force attack on credentials. The error message responses provide authentication hints, facilitating the development of such an attack.
Recommendations
For Weintek Weincloud version 0.13.6, consider temporarily restricting access to the authentication mechanism to minimize the risk of exploitation. As a workaround, limit the number of authentication attempts from a single IP address within a certain time frame until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weintek Weincloud