Back
CVE-2018-5469
CRITICAL
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.
Published: Mar 6, 2018
Modified: Jun 17, 2026
CWE-307
CWE-307
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (134)
| Vendor | Product | Version |
|---|---|---|
| belden | hirschmann_rs20-0900mmm2tdau | - |
| belden | hirschmann_rs20-0900nnm4tdau | - |
| belden | hirschmann_rs20-0900vvm2tdau | - |
| belden | hirschmann_rs20-1600l2l2sdau | - |
| belden | hirschmann_rs20-1600l2m2sdau | - |
| belden | hirschmann_rs20-1600l2s2sdau | - |
| belden | hirschmann_rs20-1600l2t1sdau | - |
| belden | hirschmann_rs20-1600m2m2sdau | - |
| belden | hirschmann_rs20-1600m2t1sdau | - |
| belden | hirschmann_rs20-1600s2m2sdau | - |
| belden | hirschmann_rs20-1600s2s2sdau | - |
| belden | hirschmann_rs20-1600s2t1sdau | - |
| belden | hirschmann_rsr20 | - |
| belden | hirschmann_rsr30 | - |
| belden | hirschmann_rsb20-0800m2m2saab | - |
| belden | hirschmann_rsb20-0800m2m2saabe | - |
| belden | hirschmann_rsb20-0800m2m2taab | - |
| belden | hirschmann_rsb20-0800m2m2taabe | - |
| belden | hirschmann_rsb20-0800s2s2saab | - |
| belden | hirschmann_rsb20-0800s2s2saabe | - |
…and 114 more
GitHub Security Advisory GHSA-m538-hxpg-3fvh
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden...
References (4)
- http://www.securityfocus.com/bid/103340 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01 Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103340 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-065-01 Mitigation, Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.84%
Top 15% most likely to be exploited
Threat Score
40.1 / 100
Data Sources
NVD
EPSS
GitHub