VulnerabilityAnalyzed
CVE-2024-3461
KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
MEDIUM 5.5EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-307
- Affected
- kioware/kioware
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2024/04/CVE-2024-3459Broken Link, Third Party Advisory
- https://cert.pl/posts/2024/04/CVE-2024-3459Broken Link, Third Party Advisory
- https://www.kioware.com/Product
- https://cert.pl/en/posts/2024/04/CVE-2024-3459Broken Link, Third Party Advisory
- https://cert.pl/posts/2024/04/CVE-2024-3459Broken Link, Third Party Advisory
- https://www.kioware.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.