PT-2024-7649 · Unknown · Location Intelligence

Published

2024-08-13

·

Updated

2024-08-14

·

CVE-2024-41682

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Location Intelligence family versions prior to V4.4
Description A vulnerability has been identified in the Location Intelligence family, where affected products do not properly enforce restrictions on excessive authentication attempts. This could allow an unauthenticated remote attacker to conduct brute force attacks against legitimate user passwords. The issue is related to insufficient limitation of authentication attempts, which may enable an attacker to perform a brute force attack.
Recommendations For versions prior to V4.4, update to version V4.4 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication attempt restrictions or rate limiting to minimize the risk of exploitation. Restrict access to authentication endpoints to reduce the likelihood of brute force attacks.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09090
CVE-2024-41682

Affected Products

Location Intelligence