Skip to main content

Improper Restriction of Excessive Authentication Attempts

CVE-2022-2822

Severity High
Score 7.5/10

Summary

The package OctoPrint through 1.8.2 is said to have a brute-force vulnerability where an attacker can freely brute force the username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-307 - Improper Restriction of Excessive Authentication Attempts

The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.

Advisory Timeline

  • Published