ZeroHour

CVE-2020-11650

CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description

An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length of an authentication message or the rate at which such messages are sent.

Vendors
ixsystems
Products
freenas firmware, truenas firmware
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.