Vulnerabilities > CVE-2020-29136 - Improper Restriction of Excessive Authentication Attempts vulnerability in Cpanel

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cpanel
CWE-307

Summary

In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

Vulnerable Configurations

Part Description Count
Application
Cpanel
339