vendor:
SureMDM On-premise
by:
Jonas Benjamin Friedli
4.1
CVSS
MEDIUM
CAPTCHA Bypass User Enumeration
285
CWE
Product Name: SureMDM On-premise
Affected Version From: <= 6.31
Affected Version To: 6.31
Patch Exists: NO
Related CWE: CVE-2023-3897
CPE: a:42gears:suremdm_on-premise:6.31
Platforms Tested:
2023
SureMDM On-premise <= 6.31 - CAPTCHA Bypass User Enumeration
The SureMDM On-premise version 6.31 and below allows attackers to bypass CAPTCHA protection by enumerating valid user IDs, potentially leading to unauthorized access. This vulnerability has been assigned CVE-2023-3897.
Mitigation:
To mitigate this issue, vendors should implement additional security measures such as stronger CAPTCHA mechanisms, rate limiting, and account lockouts after multiple failed attempts.