CVE-2024-7292: Account Controller allows high count of login attempts
Published Oct 9, 2024
·Updated
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
Affected Software
1 affected component
Progress Telerik Report Server<10.2.24.806
Event History
Oct 9, 2024
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7292?
CVE-2024-7292 is considered a high severity vulnerability due to its potential for credential stuffing attacks.
2
How do I fix CVE-2024-7292?
To mitigate CVE-2024-7292, upgrade to Progress Telerik Report Server version 2024 Q3 (10.2.24.806) or later.
3
What does CVE-2024-7292 affect?
CVE-2024-7292 affects all versions of Progress Telerik Report Server prior to 2024 Q3 (10.2.24.806).
4
What kind of attack does CVE-2024-7292 allow?
CVE-2024-7292 enables attackers to perform credential stuffing attacks due to improper restrictions on login attempts.
5
Is there a workaround for CVE-2024-7292 prior to upgrading?
While the recommended action is to upgrade, implementing rate limiting for login attempts may help mitigate the risk of CVE-2024-7292.