First published: Wed Dec 20 2023(Updated: )
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files | <23.12.13205.0 |
Update to patched version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6912 is classified as a high-severity vulnerability due to its potential to allow unlimited brute force authentication attempts.
To fix CVE-2023-6912, upgrade your M-Files Server to version 23.12.13205.0 or later.
CVE-2023-6912 allows attackers to perform brute force attacks, enabling them to exhaustively attempt to guess passwords.
The potential consequences of CVE-2023-6912 include compromised M-Files user accounts if passwords are successfully guessed by an attacker.
All versions of M-Files Server prior to 23.12.13205.0 are affected by CVE-2023-6912.