HIGH
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters)
Published Dec 23, 2020
7.5
HIGHCVSS 3.1
EPSS 1.37%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.