Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48644

Опубликовано: 22 окт. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames.

EPSS

Процентиль: 81%
0.01516
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames.

EPSS

Процентиль: 81%
0.01516
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203