CVE-2016-2944
CRITICALIBM Bigfix Remote Control < 9.1.2 - Authentication Bypass
Title source: ruleDescription
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
Scores
CVSS v3
9.8
EPSS
0.0050
EPSS Percentile
65.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
ibm/bigfix_remote_control
< 9.1.2
Timeline
Published
Nov 30, 2016
Tracked Since
Feb 18, 2026