Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47086

Опубликовано: 19 сент. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response.

Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
Версия до 4.0.0.7 (исключая)
Конфигурация 2
cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
Версия до 24.8.21.1 (исключая)

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-302
NVD-CWE-Other

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-302
NVD-CWE-Other