This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.
History

Wed, 18 Sep 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:reedos:aim-star:2.0.1:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 11 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Reedos
Reedos aim-star
CPEs cpe:2.3:a:reedos:aim-star:*:*:*:*:*:*:*:*
Vendors & Products Reedos
Reedos aim-star
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 12:15:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.
Title No Rate Limiting Vulnerability
Weaknesses CWE-799
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-09-11T11:56:43.217Z

Updated: 2024-09-11T13:31:03.180Z

Reserved: 2024-09-09T11:02:56.323Z

Link: CVE-2024-45788

cve-icon Vulnrichment

Updated: 2024-09-11T13:30:54.738Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-11T12:15:02.230

Modified: 2024-09-18T19:57:10.203

Link: CVE-2024-45788

cve-icon Redhat

No data.