SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5469

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches.

CRITICAL 9.8EPSS 2.84%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.84% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-307
Affected
belden/hirschmann rs20-0900mmm2tdau · belden/hirschmann rs20-0900nnm4tdau · belden/hirschmann rs20-0900vvm2tdau · belden/hirschmann rs20-1600l2l2sdau · belden/hirschmann rs20-1600l2m2sdau · belden/hirschmann rs20-1600l2s2sdau · belden/hirschmann rs20-1600l2t1sdau · belden/hirschmann rs20-1600m2m2sdau · belden/hirschmann rs20-1600m2t1sdau · belden/hirschmann rs20-1600s2m2sdau · belden/hirschmann rs20-1600s2s2sdau · belden/hirschmann rs20-1600s2t1sdau · belden/hirschmann rsr20 · belden/hirschmann rsr30 · belden/hirschmann rsb20-0800m2m2saab · belden/hirschmann rsb20-0800m2m2saabe · belden/hirschmann rsb20-0800m2m2taab · belden/hirschmann rsb20-0800m2m2taabe · belden/hirschmann rsb20-0800s2s2saab · belden/hirschmann rsb20-0800s2s2saabe · +40 more
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.