Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://openc3.com/ | product |
https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/ | exploit mitigation third party advisory |