Description
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of failed authentication attempts, because concurrent attempts are mishandled.
References (2)
Core 2
Core References
Various Sources
https://reserge.org/probabilistically-breaking-securenvoy-totp/
Scores
CVSS v3
3.5
EPSS
0.0019
EPSS Percentile
8.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
Status
published
Products (1)
SecurEnvoy/SecurAccess
< 9.4.515
Published
Mar 19, 2025
Tracked Since
Feb 18, 2026