Impact
The SMS one‑time‑password flow in WSO2 Identity Server fails to properly handle error messages during OTP initiation, allowing an attacker to determine system. This discovery provides a foothold for further attacks, such as brute‑force credential attempts and social engineering, which can.
Affected Systems
The affected product is WSO2 Identity Server. No specific version information is provided in the advisory, so all versions of the product may be impacted until a fix is released.
Risk and Exploitability
The CVSS score of 3.7 indicates a low impact to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a very low probability that the vulnerability will be actively exploited. The advisory notes that the vulnerability is not listed in the CISA KeV catalog. Based on the description, the likely attack vector is remote access to the SMS OTP API endpoint, which an unauthenticated attacker could use to trigger identification responses. An attacker would exploit the server’s inconsistent replies to infer does not provide a direct means to gain further privileges, the overall risk to a single system is low, but the enumeration can facilitate future credential‑guessing campaigns.
OpenCVE Enrichment