Description
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.binardat.com/...al-fanless-fiber-binardat-network-switch
www.vulncheck.com/...work-switch-missing-login-rate-limiting