GHSA-j6g5-p62x-58hwLow

vantage6 lacks brute-force protection on change password functionality

Published
June 12, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct

Patches

This issue has been patched in version 4.11.0

Workarounds

None

🎯 Affected products1

  • pip/vantage6:< 4.11.0

🔗 References (5)