PT-2024-20545 · Casaos · Casaos
Drdark1999
·
Published
2024-03-06
·
Updated
2024-03-18
·
CVE-2024-24767
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CasaOS versions 0.4.4.3 through 0.4.6
Description
The CasaOS web application lacks control over login attempts, allowing attackers to perform password brute force attacks and gain full access to the server with super user-level access.
Recommendations
For versions 0.4.4.3 through 0.4.6, update to version 0.4.7 to resolve the issue.
As a temporary workaround, consider restricting access to the login functionality until a patch is applied.
Avoid using the web application for critical operations until the issue is resolved.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Casaos