ZeroHour

CVE-2022-32515

CVSS 3.1
9.8 critical
EPSS
<1%p49
Published
()
Modified
Description

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)

Vendors
schneider-electric
Products
conext combox firmware
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.