Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.
2022-06-02T21:15:07.827
2024-11-21T06:58:27.497
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | unity_operating_environment | < 5.2.0.0.5.173 | Yes |
Application | dell | unity_xt_operating_environment | < 5.2.0.0.5.173 | Yes |
Application | dell | unityvsa_operating_environment | < 5.2.0.0.5.173 | Yes |