CVE-2023-4094
19.09.2023, 14:15
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.Enginsight
Vendor | Product | Version |
---|---|---|
fujitsu | arconte_aurea | 1.5.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1390 - Weak AuthenticationThe product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.