Fiche vulnérabilité
CVE-2024-51557 : faille moyenne 63moons aero (CVSS 6.5)
Description
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
En bref
- Sévérité
- Moyenne (CVSS 6.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 4 nov. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- 63moons aero
- 63moons wave 2.0