A CWE-1390 "Weak Authentication" in the PIN...
High severity
Unreviewed
Published
Feb 12, 2025
to the GitHub Advisory Database
•
Updated Feb 12, 2025
Description
Published by the National Vulnerability Database
Feb 12, 2025
Published to the GitHub Advisory Database
Feb 12, 2025
Last updated
Feb 12, 2025
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.
References