Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
Solution:
Workaround:
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 | third party advisory us government resource |