PT-2025-46658 · Rest Api · Rest Api

Published

2025-11-11

·

Updated

2025-11-13

·

CVE-2025-11566

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions versions prior to 2025 (affected versions not specified)
Description An issue exists that allows an attacker on the local network to gain access to a user account by performing an arbitrary number of authentication attempts with different credentials. This is due to improper restriction of excessive authentication attempts. The issue affects the /REST/shutdownnow API endpoint. The credentials variable is subject to abuse.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2025-14355
CVE-2025-11566

Affected Products

Rest Api