Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9116 | Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations. |
Solution
The new version is available from Valmet Automation Customer Service.
Workaround
No workaround given by the vendor.
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Apr 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations. | |
| Title | Valmet DNA Lack of protection against brute force attacks | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2025-04-01T14:13:23.620Z
Reserved: 2025-01-13T12:24:46.333Z
Link: CVE-2025-0417
Updated: 2025-04-01T14:13:19.513Z
Status : Awaiting Analysis
Published: 2025-04-01T04:15:38.363
Modified: 2025-04-01T20:26:11.547
Link: CVE-2025-0417
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:28Z
EUVD