Description
This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response.

Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
Published: 2024-09-19
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade Apex Softcell LD DP Back Office to version 24.8.21.1

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-42269 This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
History

Thu, 26 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell ld Geo
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell ld Geo
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apexsoftcell
Apexsoftcell ld Dp Back Office
CPEs cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:*
Vendors & Products Apexsoftcell
Apexsoftcell ld Dp Back Office
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 06:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.

Thu, 19 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
Title OTP Bypass Vulnerability
Weaknesses CWE-302
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Apexsoftcell Ld Dp Back Office Ld Geo
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2024-09-19T14:22:31.163Z

Reserved: 2024-09-18T08:36:36.214Z

Link: CVE-2024-47086

cve-icon Vulnrichment

Updated: 2024-09-19T14:22:24.375Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-19T06:15:03.227

Modified: 2024-09-26T15:29:47.233

Link: CVE-2024-47086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses