VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/7225 | third party advisory vdb entry |
http://ciac.llnl.gov/ciac/bulletins/d-06.shtml | patch government resource us government resource vendor advisory broken link third party advisory |