RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Identityautomation rapididentity
CPEs cpe:2.3:a:identityautomation:rapididentity:*:*:*:*:cloud:*:*:*
cpe:2.3:a:identityautomation:rapididentity:*:*:*:*:lts:*:*:*
Vendors & Products Identityautomation rapididentity

Thu, 05 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Identityautomation
Identityautomation rapididentity Cloud
Identityautomation rapididentity Lts
Weaknesses CWE-307
CPEs cpe:2.3:a:identityautomation:rapididentity_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:identityautomation:rapididentity_lts:*:*:*:*:*:*:*:*
Vendors & Products Identityautomation
Identityautomation rapididentity Cloud
Identityautomation rapididentity Lts
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 16:15:00 +0000

Type Values Removed Values Added
Description RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-05T18:00:23.316Z

Reserved: 2024-09-02T00:00:00

Link: CVE-2024-45589

cve-icon Vulnrichment

Updated: 2024-09-05T17:57:10.868Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T16:15:08.737

Modified: 2024-09-12T16:54:09.467

Link: CVE-2024-45589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.