Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-51561

Опубликовано: 04 нояб. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process.

Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:63moons:aero:*:*:*:*:*:*:*:*
Версия до 120820241550 (исключая)
cpe:2.3:a:63moons:wave_2.0:*:*:*:*:*:*:*:*
Версия до 1.1.7 (исключая)

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-807
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.

EPSS

Процентиль: 23%
0.00075
Низкий

7.5 High

CVSS3

Дефекты

CWE-807
NVD-CWE-Other