PT-2023-32820 · M Files · M-Files Server

CVE-2023-6912

·

Publicado

2023-12-20

·

Atualizado

2026-02-23

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 23.12.13205.0
Description The issue is related to a lack of protection against brute force attacks, allowing an attacker to make unlimited authentication attempts. This could potentially compromise targeted M-Files user accounts by guessing passwords.
Recommendations For versions prior to 23.12.13205.0, update to version 23.12.13205.0 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication security measures, such as rate limiting or account lockout policies, to minimize the risk of exploitation.

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-6912

Produtos afetados

M-Files Server