Skip to content
COOEY

EXPOSURES › CVE-2023-24080

CVE-2023-24080

CRITICAL
DETAIL
SourceNVD · cve Published2023-02-21 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-24080 ↗
SHAME 35/100

A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.