Impact
The vulnerability in WSO2 Identity Server permits OTPs used in MFA to remain valid indefinitely, allowing attackers to repeat OTP guesses without time constraints. This missing expiration enables brute force attempts that can ultimately bypass MFA, leading to unauthorized account takeover and compromising user privacy and system integrity. The weakness is identified as CWE-613, indicating a failure to enforce proper authentication controls.
Affected Systems
WSO2 Identity Server is the impacted product. The advisory covers the default WSO2 Identity Server deployment, with no specific version list provided in the CNA data. Administrators should verify that their installation uses a version affected by this issue.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity. EPSS score is not available, so current exploitation probability cannot be quantified, and the vulnerability is not currently in the CISA KEV list. Attackers can exploit the lack of OTP expiration through indefinite brute force attempts, requiring only the ability to send or intercept SMS codes. The vulnerability is remote and does not depend on privileged local access. Because the OTP remains valid indefinitely, the window for a successful exploitation is effectively unlimited, increasing the risk of compromise.
OpenCVE Enrichment