PT-2024-10884 · Netiq · Netiq Advance Authentication
Published
2024-08-27
·
Updated
2024-09-13
·
CVE-2021-22530
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
NetIQ Advance Authentication versions prior to 6.3.5.1
Description
A vulnerability identified in NetIQ Advance Authentication does not enforce account lockout when a brute force attack is performed on API-based login. This issue may lead to user account compromise if successful or may impact server performance.
Recommendations
For versions prior to 6.3.5.1, update to version 6.3.5.1 to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent brute force attacks on the API-based login. Restrict access to the API endpoint to minimize the risk of exploitation. Avoid using the API-based login until the issue is resolved by updating to the recommended version.
Fix
Improper Restriction of Excessive Authentication Attempts
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netiq Advance Authentication