ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.

Project Subscriptions

Vendors Products
Fujitsu Subscribe
Arconte Aurea Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-53984 ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.
Fixes

Solution

This vulnerabilities have been fixed by Fujitsu in version 1.5.0.0, released on 4/4/2022. All new versions of the product, including the latest 1.6.2.3, also include the fixes.


Workaround

No workaround given by the vendor.

History

Wed, 25 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-25T15:31:16.724Z

Reserved: 2023-08-02T11:05:16.469Z

Link: CVE-2023-4094

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:11.863Z

cve-icon NVD

Status : Modified

Published: 2023-09-19T14:15:22.833

Modified: 2024-11-21T08:34:22.733

Link: CVE-2023-4094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses