Impact
Cockpit CMS versions before 2.14.1 contain a timing-based vulnerability in the authentication endpoint. The server performs bcrypt verification only for existing accounts, while non‑existent accounts return immediately, creating measurable response time differences. An attacker can repeat authentication requests and observe these differences to determine which user names are valid. Based on the description, it is inferred that enumerating accounts could facilitate higher‑risk attacks such as targeted phishing, credential guessing, and privilege escalation once valid accounts are identified.
Affected Systems
The vulnerability affects the Cockpit CMS product from Cockpit‑HQ in all releases prior to 2.14.1.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The vulnerability is exploitable remotely by anyone who can reach the public authentication endpoint and send repeated requests. No publicly available exploits are reported and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available; however, account enumeration is a common preparatory step that can aid further attacks.
OpenCVE Enrichment