CVE-2024-3461

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
References
Link Resource
https://cert.pl/en/posts/2024/04/CVE-2024-3459 Broken Link Third Party Advisory
https://cert.pl/posts/2024/04/CVE-2024-3459 Broken Link Third Party Advisory
https://www.kioware.com/ Product
https://cert.pl/en/posts/2024/04/CVE-2024-3459 Broken Link Third Party Advisory
https://cert.pl/posts/2024/04/CVE-2024-3459 Broken Link Third Party Advisory
https://www.kioware.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:kioware:kioware:*:*:*:*:*:windows:*:*

History

12 Feb 2025, 15:37

Type Values Removed Values Added
References () https://cert.pl/en/posts/2024/04/CVE-2024-3459 - () https://cert.pl/en/posts/2024/04/CVE-2024-3459 - Broken Link, Third Party Advisory
References () https://cert.pl/posts/2024/04/CVE-2024-3459 - () https://cert.pl/posts/2024/04/CVE-2024-3459 - Broken Link, Third Party Advisory
References () https://www.kioware.com/ - () https://www.kioware.com/ - Product
CPE cpe:2.3:a:kioware:kioware:*:*:*:*:*:windows:*:*
First Time Kioware
Kioware kioware

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://cert.pl/en/posts/2024/04/CVE-2024-3459 - () https://cert.pl/en/posts/2024/04/CVE-2024-3459 -
References () https://cert.pl/posts/2024/04/CVE-2024-3459 - () https://cert.pl/posts/2024/04/CVE-2024-3459 -
References () https://www.kioware.com/ - () https://www.kioware.com/ -
Summary
  • (es) KioWare para Windows (versiones hasta 8.35) permite forzar el número PIN por fuerza bruta, lo que protege la aplicación contra el cierre, ya que no existen mecanismos que impidan que un usuario adivine excesivamente el número.

14 May 2024, 15:41

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:41

Updated : 2025-02-12 15:37


NVD link : CVE-2024-3461

Mitre link : CVE-2024-3461

CVE.ORG link : CVE-2024-3461


JSON object : View

Products Affected

kioware

  • kioware
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts