LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to leverage this vulnerability to gain access to user accounts. This issue has been addressed in version 23.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References
Link | Resource |
---|---|
https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx | Exploit Vendor Advisory |
https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx | Exploit Vendor Advisory |
Configurations
History
21 Nov 2024, 08:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - Exploit, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
25 Nov 2023, 01:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Librenms
Librenms librenms |
|
References | () https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx - Exploit, Vendor Advisory | |
CPE | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* |
17 Nov 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-17 22:15
Updated : 2024-11-21 08:29
NVD link : CVE-2023-46745
Mitre link : CVE-2023-46745
CVE.ORG link : CVE-2023-46745
JSON object : View
Products Affected
librenms
- librenms
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts