CVE-2023-4094: Weak authentication vulnerability in Fujitsu Arconte Áurea
Published Sep 19, 2023
·Updated
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.
Affected Software
1 affected component
Fujitsu ARCONTE Aurea=1.5.0.0
Remediation
Information
This vulnerabilities have been fixed by Fujitsu in version 1.5.0.0, released on 4/4/2022. All new versions of the product, including the latest 1.6.2.3, also include the fixes.
Event History
Sep 19, 2023
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4094.
2
What is the severity rating of CVE-2023-4094?
CVE-2023-4094 has a severity rating of 8.2 (high).
3
What software version is affected by CVE-2023-4094?
CVE-2023-4094 affects ARCONTE Aurea version 1.5.0.0.
4
How can an attacker exploit CVE-2023-4094?
An attacker can exploit CVE-2023-4094 by making incorrect access requests to block legitimate accounts and cause a denial of service.
5
Is there a fix available for CVE-2023-4094?
Please refer to the vendor's advisory or contact the vendor for information on available fixes for CVE-2023-4094.