THREAT OPS › Threat News › [NVD] CVE-2024-6832 (MEDIUM 5.9) — The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid
[NVD] CVE-2024-6832 (MEDIUM 5.9) — The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid
CVE-2024-6832 CVSS: 5.9 MEDIUM Published: 2026-08-06T08:16:27.533
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2024-6832cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-6832