First published: Tue Apr 18 2023(Updated: )
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Netbotz 355 Firmware | >=4.0.0<=4.7.0 | |
Schneider-electric Netbotz 355 | ||
Schneider-electric Netbotz 450 Firmware | >=4.0.0<=4.7.0 | |
Schneider-electric Netbotz 450 | ||
Schneider-electric Netbotz 455 Firmware | >=4.0.0<=4.7.0 | |
Schneider-electric Netbotz 455 | ||
Schneider-electric Netbotz 550 Firmware | >=4.0.0<=4.7.0 | |
Schneider-electric Netbotz 550 | ||
Schneider-electric Netbotz 570 Firmware | >=4.0.0<=4.7.0 | |
Schneider-electric Netbotz 570 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43377.
The title of the vulnerability is A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could…
The severity of CVE-2022-43377 is high with a CVSS score of 7.5.
The affected products are NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior).
CVE-2022-43377 can be exploited through a brute force attack on the account, causing account takeover.