This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apexsoftcell ld Dp Back Office
|
|
CPEs | cpe:2.3:a:apexsoftcell:ld_dp_back_office:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apexsoftcell ld Dp Back Office
|
|
Metrics |
cvssV3_1
|
Thu, 19 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apexsoftcell
Apexsoftcell ld Geo |
|
CPEs | cpe:2.3:a:apexsoftcell:ld_geo:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apexsoftcell
Apexsoftcell ld Geo |
|
Metrics |
ssvc
|
Thu, 19 Sep 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts. | |
Title | User Enumeration vulnerability | |
Weaknesses | CWE-307 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-In
Published: 2024-09-19T06:13:40.801Z
Updated: 2024-09-19T13:47:33.613Z
Reserved: 2024-09-18T08:36:36.215Z
Link: CVE-2024-47088
Vulnrichment
Updated: 2024-09-19T13:47:27.995Z
NVD
Status : Analyzed
Published: 2024-09-19T07:15:02.507
Modified: 2024-09-26T19:12:58.083
Link: CVE-2024-47088
Redhat
No data.