This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
History

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell
Apexsoftcell ld Dp Back Office
CPEs cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell
Apexsoftcell ld Dp Back Office
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 06:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.

Thu, 19 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
Title OTP Bypass Vulnerability
Weaknesses CWE-302
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-09-19T06:03:10.218Z

Updated: 2024-09-19T14:22:31.163Z

Reserved: 2024-09-18T08:36:36.214Z

Link: CVE-2024-47086

cve-icon Vulnrichment

Updated: 2024-09-19T14:22:24.375Z

cve-icon NVD

Status : Received

Published: 2024-09-19T06:15:03.227

Modified: 2024-09-19T07:15:02.273

Link: CVE-2024-47086

cve-icon Redhat

No data.