PT-2024-24730 · Unknown · Yms Vis Pro
Remediata
·
Published
2024-05-13
·
Updated
2024-05-14
·
CVE-2024-3263
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YMS VIS Pro versions prior to 3.3.0.7
Description
The issue arises from a combination of an improper method for system credentials generation and a weak password policy, allowing passwords to be easily guessed and enumerated through brute force attacks. This can lead to unauthorized access and the execution of operations based on assigned user permissions.
Recommendations
For versions prior to 3.3.0.7, update the authentication mechanisms and implement an additional authentication layer along with strong password policies to mitigate the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yms Vis Pro