CyberArk Endpoint Privilege Manager
cpe:2.3:a:cyberark:endpoint_privilege_manager:*:*:*:*:*:*:*
- 24.7.1
A vulnerability exists in CyberArk Endpoint Privilege Manager SaaS version 24.7.1, allowing brute force attacks on user passwords via the '/EPMUI/VfManager.asmx/ChangePassword' endpoint. The application fails to limit the number or frequency of user interactions, enabling attackers to repeatedly attempt to guess passwords. This vulnerability could be exploited by anyone with access to the affected application.
Exploitation of this vulnerability allows for successful brute force attacks on user passwords, potentially leading to unauthorized account access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.