CVE-2021-28248

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References
Link Resource
https://n4nj0.github.io/advisories/ca-ehealth-performance-manager/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:ehealth:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:32

Type Values Removed Values Added
Summary ** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer. CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CPE cpe:2.3:a:ca:ehealth:*:*:*:*:*:*:*:* cpe:2.3:a:broadcom:ehealth:*:*:*:*:*:*:*:*
First Time Broadcom
Broadcom ehealth

29 Mar 2021, 16:36

Type Values Removed Values Added
CPE cpe:2.3:a:ca:ehealth:*:*:*:*:*:*:*:*
CWE CWE-307
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://n4nj0.github.io/advisories/ca-ehealth-performance-manager/ - (MISC) https://n4nj0.github.io/advisories/ca-ehealth-performance-manager/ - Exploit, Third Party Advisory

26 Mar 2021, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-26 08:15

Updated : 2024-04-11 01:11


NVD link : CVE-2021-28248

Mitre link : CVE-2021-28248

CVE.ORG link : CVE-2021-28248


JSON object : View

Products Affected

broadcom

  • ehealth
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts