Vulnerabilities > CVE-2022-37144 - Improper Restriction of Excessive Authentication Attempts vulnerability in Plextrac
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |