The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5635 | vdb entry vendor advisory broken link third party advisory |
http://www.iss.net/security_center/static/9349.php | vendor advisory broken link vdb entry |
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21089 | third party advisory broken link |
http://www.polycom.com/common/pw_item_show_doc/0%2C%2C1444%2C00.pdf | product |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44241 | third party advisory vdb entry |
http://www.ciac.org/ciac/bulletins/m-123.shtml | patch vendor advisory broken link government resource third party advisory |