Description
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vulnerability affects VIS Pro in versions <= 3.3.0.6. This vulnerability has been mitigated by changes in authentication mechanisms and implementation of additional authentication layer and strong password policies.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31854 | YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vulnerability affects VIS Pro in versions <= 3.3.0.6. This vulnerability has been mitigated by changes in authentication mechanisms and implementation of additional authentication layer and strong password policies. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: SK-CERT
Published:
Updated: 2024-08-01T20:05:08.248Z
Reserved: 2024-04-03T11:57:41.321Z
Link: CVE-2024-3263
Updated: 2024-08-01T20:05:08.248Z
Status : Deferred
Published: 2024-05-14T15:40:35.000
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-3263
No data.
OpenCVE Enrichment
No data.
EUVD