PT-2023-32820 · M Files · M-Files Server

CVE-2023-6912

·

Published

2023-12-20

·

Updated

2026-02-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 23.12.13205.0
Description The issue is related to a lack of protection against brute force attacks, allowing an attacker to make unlimited authentication attempts. This could potentially compromise targeted M-Files user accounts by guessing passwords.
Recommendations For versions prior to 23.12.13205.0, update to version 23.12.13205.0 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication security measures, such as rate limiting or account lockout policies, to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6912

Affected Products

M-Files Server