CVE-2024-47088
19.09.2024, 07:15
This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.Enginsight
Vendor | Product | Version |
---|---|---|
apexsoftcell | ld_geo | 𝑥 < 4.0.0.7 |
apexsoftcell | ld_dp_back_office | 𝑥 < 24.8.21.1 |
𝑥
= Vulnerable software versions