CVE-2020-14494
Summary
| CVE | CVE-2020-14494 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-20 15:15:00 UTC |
| Updated | 2021-11-04 18:22:00 UTC |
| Description | OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openclinic Ga Project | Openclinic Ga | 5.09.02 | All | All | All |
| Application | Openclinic Ga Project | Openclinic Ga | 5.89.05b | All | All | All |
| Application | Openclinic Ga Project | Openclinic Ga | 5.09.02 | All | All | All |
| Application | Openclinic Ga Project | Openclinic Ga | 5.89.05b | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenClinic GA | CISA | MISC | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.