Back

MEDIUM

The login functionality of the web server in affected devices does not normalize the response times of login attempts

Published Feb 11, 2025

Description

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner siemens
Published Feb 11, 2025
Updated Apr 8, 2025
Reserved Jul 6, 2023

CISA Vulnrichment

Updated Feb 11, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner siemens
Published Feb 11, 2025
Updated Apr 8, 2025

GitHub

No data