In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://documentation.mersive.com/content/pages/release-notes.htm | release notes vendor advisory |
https://www.mersive.com/uk/products/solstice/ | product vendor advisory |
https://github.com/aress31/solstice-pod-cves | third party advisory exploit |