Impact
The vulnerability arises when a Tempo KeyAuthorization contains all the subscription parameters but is not tied to the challenge that requested it. Because the signed fields do not reference the particular challenge, an attacker who intercepts an activation credential can replay it under a new challenge, causing the server to accept the activation again. As a result, the payer’s wallet is charged multiple times for the same subscription period, leading to unauthorized financial losses.
Affected Systems
ZenHive's MPP product is affected in all releases from version 0.14.0 up to (but not including) 0.16.2. Any deployment running one of these versions is vulnerable if the subscription activation process uses Tempo KeyAuthorizations.
Risk and Exploitability
With a CVSS score of 8.2 and no listed KEV entry, the vulnerability is considered high severity. The EPSS score is not available, so the exact exploitation probability cannot be quantified, but replay attacks can be performed with little effort once a credential is captured. The attacker would need only the signed KeyAuthorization and the ability to submit it to the server; no additional code execution or privileged access is required. The vulnerability is not known to be actively exploited in the wild, but the potential for financial impact is substantial.
OpenCVE Enrichment