{"Brute Force Attacks Can Bypass Weak Password Policy in YMS VIS Pro","Unauthorized Access and Operation Execution via Improper Credentials Generation"}
CVE-2024-3263
Key Information:
- Vendor
- Yms
- Status
- Vis Pro
- Vendor
- CVE Published:
- 14 May 2024
Summary
YMS VIS Pro, an information system designed for veterinary and food administration, is susceptible to important security concerns due to its method of system credential generation and inadequate password policies. These issues allow for easy guessing and enumeration of passwords, making the system vulnerable to brute force attacks. If exploited, these vulnerabilities can permit unauthorized access, enabling attackers to perform actions based on the compromised user permissions. To address these security flaws, recent updates have introduced enhancements in authentication mechanisms, alongside the implementation of stronger password policies and an additional authentication layer.
Affected Version(s)
VIS Pro 0 <= 3.3.0.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved