Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
Solution:
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10091-12462-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10090-112f7-2.html | third party advisory |