Vulnerabilities > CVE-2020-8228 - Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
nextcloud
opensuse
CWE-307

Summary

A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

Vulnerable Configurations

Part Description Count
Application
Nextcloud
1
Application
Opensuse
2
OS
Opensuse
2