Improper Restriction of Excessive Authentication Attempts in Kiwi - CVE-2023-25156
Published: February 15, 2023 / Updated: September 18, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to gain unauthorized access.
The vulnerability exists due to improper restriction of excessive authentication attempts in the login page when submitting repeated login attempts. An attacker with physical access can submit repeated login attempts to gain unauthorized access.