Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
4.0
affected
Description
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
4.0
References
www.twcert.org.tw/tw/cp-132-10091-12462-1.html
www.twcert.org.tw/en/cp-139-10090-112f7-2.html