EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- •Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: 0.5%CVSS: 5.9Exploit: None knownExposed services: Not assessed
A fix is referenced (a reference tagged "Patch", often a source commit), but no release containing it is confirmed — find the release that contains it; until it is applied, mitigate (WAF / firewall / segmentation).
Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the !== used for comparison.
The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute
CISA SSVCTrack at every mission impact level.
A fix is referenced, but no release containing it is confirmed. Check the referenced fix and the vendor's advisory for a release that contains it and apply that within your standard update timelines; until then, restrict network exposure of the affected system or apply the vendor's mitigation.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table