Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://info.cryptobox.com/doc/v4.40/4.40.en/ |
|
Wed, 29 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ercom:cryptobox:4.40.175:*:*:*:*:*:*:* |
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request. | |
| Title | Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout | |
| First Time appeared |
Ercom
Ercom cryptobox |
|
| Weaknesses | CWE-694 | |
| CPEs | cpe:2.3:a:ercom:cryptobox:*:*:*:*:*:*:*:* cpe:2.3:a:ercom:cryptobox:4.40.175:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ercom
Ercom cryptobox |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2026-04-29T14:06:08.155Z
Reserved: 2026-04-08T13:20:07.168Z
Link: CVE-2026-5794
Updated: 2026-04-28T18:33:53.379Z
Status : Awaiting Analysis
Published: 2026-04-28T19:37:47.390
Modified: 2026-04-28T20:10:23.367
Link: CVE-2026-5794
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:15:43Z