説明
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)
AI分析AIによる分析
影響を受ける製品
schneider-electricnetbotz_355_firmware
schneider-electricnetbotz_355
-
schneider-electricnetbotz_450_firmware
schneider-electricnetbotz_450
-
schneider-electricnetbotz_455_firmware
schneider-electricnetbotz_455
-
schneider-electricnetbotz_550_firmware
schneider-electricnetbotz_550
-
schneider-electricnetbotz_570_firmware
schneider-electricnetbotz_570
-
参照
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdfPatchVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdfPatchVendor Advisory