CVE-2020-12645Improper Restriction of Excessive Authentication Attempts in Appsuite

Severity
9.8CRITICALNVD
EPSS
0.3%
top 43.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 24

Description

OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDopen-xchange/open-xchange_appsuite7.10.17.10.3

🔴Vulnerability Details

2
GHSA
GHSA-9753-9pqh-vm76: OX App Suite 72022-05-24
CVEList
CVE-2020-12645: OX App Suite 72020-08-31
CVE-2020-12645 — Open-xchange Appsuite vulnerability | cvebase