Vulnerabilities > CVE-2023-33759 - Improper Restriction of Excessive Authentication Attempts vulnerability in Splicecom Maximiser Soft PBX

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
splicecom
CWE-307
critical

Summary

SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.

Vulnerable Configurations

Part Description Count
Application
Splicecom
1