Improper Restriction of Excessive Authentication Attempts in Schneider Electric's Conext™ ComBox
CVE-2022-32515
8.6HIGH
What is CVE-2022-32515?
A vulnerability exists within Schneider Electric's Conext™ ComBox that permits excessive authentication attempts, potentially allowing malicious actors to execute brute force attacks. If there is no effective rate limiting mechanism implemented on the admin authentication form, attackers can exploit this vulnerability to take over admin accounts, compromising system security.
Affected Version(s)
Conext™ ComBox All Versions