VYPR
High severity7.5NVD Advisory· Published Sep 8, 2022· Updated Jul 9, 2026

CVE-2022-37145

CVE-2022-37145

Description

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Plextrac/Plextraccpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <1.17.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.