PT-2024-20545 · Casaos · Casaos

Drdark1999

·

Published

2024-03-06

·

Updated

2024-03-18

·

CVE-2024-24767

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CasaOS versions 0.4.4.3 through 0.4.6
Description The CasaOS web application lacks control over login attempts, allowing attackers to perform password brute force attacks and gain full access to the server with super user-level access.
Recommendations For versions 0.4.4.3 through 0.4.6, update to version 0.4.7 to resolve the issue. As a temporary workaround, consider restricting access to the login functionality until a patch is applied. Avoid using the web application for critical operations until the issue is resolved.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2024-24767
GHSA-C69X-5XMW-V44X
GO-2024-2614

Affected Products

Casaos