Improper Restriction of Excessive Authentication Attempts in LibreNMS - CVE-2023-46745

 

Improper Restriction of Excessive Authentication Attempts in LibreNMS - CVE-2023-46745

Published: November 17, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129751
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46745
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts in the login page authentication handler when processing GET-based authentication requests. A remote attacker can send repeated authentication requests to brute-force user accounts to disclose sensitive information.

One login method uses GET requests for authentication, which may expose submitted credentials in web server logs.


Affected software

LibreNMS

How to mitigate CVE-2023-46745

Install security update from vendor's website.

LibreNMS - update to 23.11.0

External References

Related Security Bulletins