CVE-2021-28248: High severity broadcom ehealth vulnerability
UNSUPPORTED WHEN ASSIGNED CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28248?
CVE-2021-28248 has a medium severity rating due to improper restriction of excessive authentication attempts.
How do I fix CVE-2021-28248?
To mitigate CVE-2021-28248, implement rate limiting on authentication attempts and ensure strong account lockout policies.
What software versions are affected by CVE-2021-28248?
CVE-2021-28248 affects CA eHealth Performance Manager versions up to 6.3.2.12.
What type of vulnerability is CVE-2021-28248?
CVE-2021-28248 is classified as an improper restriction of excessive authentication attempts vulnerability.
Can CVE-2021-28248 lead to unauthorized access?
Yes, CVE-2021-28248 allows attackers to perform arbitrary authentication attempts, which may lead to unauthorized access.