Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
History

Fri, 02 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 May 2025 03:30:00 +0000

Type Values Removed Values Added
Description Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
Title Flowring Technology Agentflow - Account Lockout Bypass
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-05-02T03:13:32.971Z

Updated: 2025-05-02T15:02:34.546Z

Reserved: 2025-04-16T07:44:40.099Z

Link: CVE-2025-3709

cve-icon Vulnrichment

Updated: 2025-05-02T15:02:25.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-02T04:15:55.707

Modified: 2025-05-02T13:52:51.693

Link: CVE-2025-3709

cve-icon Redhat

No data.