TROYANOSYVIRUS
Retour aux CVEs

CVE-2020-14494

CRITICAL
9.8

Description

OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie7/20/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

openclinic_ga_project:openclinic_ga

Faiblesses (CWE)

CWE-287CWE-307

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.