CVE-2024-41682

A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated remote attacker to conduct brute force attacks against legitimate user passwords.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*

History

14 Aug 2024, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:location_intelligence:*:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-720392.html - () https://cert-portal.siemens.com/productcert/html/ssa-720392.html - Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en la familia Location Intelligence (todas las versiones &lt; V4.4). Los productos afectados no aplican adecuadamente la restricción de intentos de autenticación excesivos. Esto podría permitir que un atacante remoto no autenticado realice ataques de fuerza bruta contra contraseñas de usuarios legítimos.
First Time Siemens location Intelligence
Siemens

13 Aug 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 08:15

Updated : 2024-08-14 18:37


NVD link : CVE-2024-41682

Mitre link : CVE-2024-41682

CVE.ORG link : CVE-2024-41682


JSON object : View

Products Affected

siemens

  • location_intelligence
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts