This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response.
Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apexsoftcell ld Geo
|
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apexsoftcell ld Geo
|
|
Metrics |
cvssV3_1
|
Thu, 19 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apexsoftcell
Apexsoftcell ld Dp Back Office |
|
CPEs | cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apexsoftcell
Apexsoftcell ld Dp Back Office |
|
Metrics |
ssvc
|
Thu, 19 Sep 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. | This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. |
Thu, 19 Sep 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts. | |
Title | OTP Bypass Vulnerability | |
Weaknesses | CWE-302 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-In
Published: 2024-09-19T06:03:10.218Z
Updated: 2024-09-19T14:22:31.163Z
Reserved: 2024-09-18T08:36:36.214Z
Link: CVE-2024-47086
Vulnrichment
Updated: 2024-09-19T14:22:24.375Z
NVD
Status : Analyzed
Published: 2024-09-19T06:15:03.227
Modified: 2024-09-26T15:29:47.233
Link: CVE-2024-47086
Redhat
No data.