CVE-2022-37145
plextrac
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.
- CVSS
- 7.5
- EPSS
- 0.89% 55.8% percentile
- CISA KEV
- Not listed
- Published
- 2022.09.08