Improper Restriction of Excessive Authentication Attempts in Kiwi - CVE-2023-25156

 

Improper Restriction of Excessive Authentication Attempts in Kiwi - CVE-2023-25156

Published: February 15, 2023 / Updated: September 18, 2026


Vulnerability identifier: #VU150950
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25156
CWE-ID: CWE-307
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to gain unauthorized access.

The vulnerability exists due to improper restriction of excessive authentication attempts in the login page when submitting repeated login attempts. An attacker with physical access can submit repeated login attempts to gain unauthorized access.


Affected software

Kiwi

How to mitigate CVE-2023-25156

Install security update from vendor's website.

Kiwi - update to 12.0

External References

Related Security Bulletins