{"Brute Force Attacks Can Bypass Weak Password Policy in YMS VIS Pro","Unauthorized Access and Operation Execution via Improper Credentials Generation"}
CVE-2024-3263

9.8CRITICAL

Key Information:

Vendor
Yms
Status
Vis Pro
Vendor
CVE Published:
14 May 2024

Summary

YMS VIS Pro, an information system designed for veterinary and food administration, is susceptible to important security concerns due to its method of system credential generation and inadequate password policies. These issues allow for easy guessing and enumeration of passwords, making the system vulnerable to brute force attacks. If exploited, these vulnerabilities can permit unauthorized access, enabling attackers to perform actions based on the compromised user permissions. To address these security flaws, recent updates have introduced enhancements in authentication mechanisms, alongside the implementation of stronger password policies and an additional authentication layer.

Affected Version(s)

VIS Pro 0 <= 3.3.0.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

REMEDIATA ([email protected])
.