Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.
Solution:
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.