VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.
References
Link | Resource |
---|---|
http://ciac.llnl.gov/ciac/bulletins/d-06.shtml | Broken Link Patch Third Party Advisory US Government Resource Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7225 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 1999-12-31 05:00
Updated : 2024-02-09 03:15
NVD link : CVE-1999-1324
Mitre link : CVE-1999-1324
CVE.ORG link : CVE-1999-1324
JSON object : View
Products Affected
hp
- openvms_vax
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts