Beveiligingsadvies

CVE-2026-61458

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-13 21:30:07
Laatst bijgewerkt 2026-07-14 22:03:37
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense, making short or dictionary-derived passphrases practically recoverable within hours or days.