CVE-2024-51558
04.11.2024, 13:17
This vulnerability exists in the Wave 2.0due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.Enginsight
Vendor | Product | Version |
---|---|---|
63moons | aero | 𝑥 < 120820241550 |
63moons | wave_2.0 | 𝑥 < 1.1.7 |
𝑥
= Vulnerable software versions