CVE-2025-53968

This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (DoS) condition. This can overwhelm the authentication system, rendering it unavailable to legitimate users and potentially causing service disruption. This can also allow attackers to conduct brute-force attacks to gain unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:evmapa:evmapa:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:39

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad surge porque no hay limitaciones en el número de intentos de autenticación que un usuario puede realizar. Un atacante puede explotar esta debilidad enviando continuamente solicitudes de autenticación, lo que lleva a una condición de denegación de servicio (DoS). Esto puede sobrecargar el sistema de autenticación, dejándolo no disponible para usuarios legítimos y potencialmente causando interrupción del servicio. Esto también puede permitir a los atacantes realizar ataques de fuerza bruta para obtener acceso no autorizado.

02 Feb 2026, 19:59

Type Values Removed Values Added
References () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-022-08.json - () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-022-08.json - Third Party Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08 - Third Party Advisory, US Government Resource
First Time Evmapa evmapa
Evmapa
CPE cpe:2.3:a:evmapa:evmapa:*:*:*:*:*:*:*:*

22 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 23:15

Updated : 2026-06-17 09:39


NVD link : CVE-2025-53968

Mitre link : CVE-2025-53968

CVE.ORG link : CVE-2025-53968


JSON object : View

Products Affected

evmapa

  • evmapa
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts