Vulnerabilities > CVE-2023-33754 - Improper Restriction of Excessive Authentication Attempts vulnerability in Inpiazza Cloud Wifi

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
inpiazza
CWE-307

Summary

The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.

Vulnerable Configurations

Part Description Count
Application
Inpiazza
1