PT-2026-57885 · Unknown · Password Pusher
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PasswordPusher versions prior to 2.9.2
Description
An issue exists where passphrase-protected pushes are susceptible to brute-force attacks. The 'POST /p/:token/access' endpoint lacks route-specific rate limiting and per-push lockout mechanisms. This allows an attacker who possesses a push token to systematically guess passphrases at a rate of 120 attempts per minute, potentially recovering short or dictionary-derived passphrases within hours or days.
Recommendations
Update to version 2.9.2 or later.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Password Pusher