CVE-2023-46745

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain access to user accounts. This issue has been addressed in version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:29

Type Values Removed Values Added
References () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - Exploit, Vendor Advisory () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3

25 Nov 2023, 01:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Librenms
Librenms librenms
References () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - Exploit, Vendor Advisory
CPE cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

17 Nov 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-17 22:15

Updated : 2024-11-21 08:29


NVD link : CVE-2023-46745

Mitre link : CVE-2023-46745

CVE.ORG link : CVE-2023-46745


JSON object : View

Products Affected

librenms

  • librenms
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts