Medium6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

PT-2024-72: Weakness of password policy in Password Pusher

Error type:

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Severity (CVSSv3.1): 5.3 (medium)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 6.9 (medium)

Description:

The vulnerability was identified in Password Pusher versions prior to 1.49.0.

The application allows users to set weak and easily bruteforced passwords. The discovered vulnerability allows attackers to bruteforce the password and gain access to the application with privileges of the corresponding user.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 20.11.2024

Recommendations:

  • Update to version or higher

Additional information: Positive Technologies

Identifiers:

CVE-2024-52796

Vendor:

Apnotic, LLC

Vulnerable product:

Password Pusher

Vulnerable versions:

< 1.49.0