Impact
The IRIS web application fails to protect its user authentication from brute‑force attacks, enabling an attacker to systematically guess login credentials. This weakness allows a malicious actor to gain unauthorized access to user accounts, potentially compromising sensitive data and system integrity. The flaw is classified as CWE‑770, reflecting a failure to enforce limits on authentication attempts.
Affected Systems
The vulnerability affects the DFIR‑IRIS iris‑web application, specifically version 2.4.26 and possibly other, as yet unspecified, releases. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploit at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely target the publicly exposed login interface, flooding it with repeated credential attempts until a valid combination is discovered.
OpenCVE Enrichment