Impact
The vulnerability in Drupal Commerce CyberSource is an observable timing discrepancy caused by insufficient input validation. It allows an attacker to perform brute‑force attempts against authentication or transaction validation routines, potentially elevating privileges or executing fraudulent operations. This weakness is classified as CWE‑208, which concerns improper input validation that can be exploited through timing attacks.
Affected Systems
Drupal Commerce CyberSource is affected. All versions from 0.0.0 up to and including 1.10.0 contain the flaw. No specific sub‑versions or patch releases are listed as mitigated.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not currently listed in CISA KEV, indicating no known active exploitation at the time of disclosure. However, the flaw permits brute‑force attacks by measuring response times, making it exploitable if an attacker can send repeated requests to the affected endpoints, which is inferred to be the web or API interfaces of the module. The lack of severity metrics in the data does not diminish the potential impact, as the flaw could enable unauthorized access or financial fraud.
OpenCVE Enrichment