PT-2024-29624 · Unknown · Sinec Traffic Analyzer
Published
2024-08-13
·
Updated
2024-08-17
·
CVE-2024-41904
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SINEC Traffic Analyzer versions prior to V2.0
Description
A vulnerability has been identified in the SINEC Traffic Analyzer where the affected application does not properly enforce restrictions on excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.
Recommendations
For versions prior to V2.0, update to V2.0 to stay secure. As a temporary workaround, consider restricting access to the application to minimize the risk of exploitation. Avoid using the application for critical authentication processes until the issue is resolved.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinec Traffic Analyzer