Impact
The updated description indicates that Universal Software Inc. FlexCity suffers from improper restriction of excessive authentication attempts, potentially allowing an attacker to repeatedly try authentication without limit. This can lead to bypassing the one‑time password mechanism and gaining unauthorized access, which aligns with CWE‑307.
Affected Systems
Universal Software Inc. FlexCity versions 5.536.0 up to, but not including, 5.542.0 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, based on the description that repeated authentication attempts could be made over a network connection to the FlexCity application.
OpenCVE Enrichment