CRITICAL🇵🇱 Wersja polska

CVE-2024-47088

CVSS 9.3v4.0pub. 2024-09-19upd. 2024-09-26

This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.

🤖 AI Analysis
How it works

The application does not implement restrictions on the number of failed login attempts (CWE-307) on API endpoints handling OTP authentication. An attacker can automatically send successive login requests, systematically checking possible OTP values. Due to the limited range of typical OTP code values, the attack can succeed in a short time. No permissions or victim interaction are required.

Impact

An attacker can gain unauthorized access to accounts of other system users. This results in a breach of confidentiality and integrity of data available in the context of compromised accounts.

Mitigation & patch

Apply patches available from the vendor according to the references. Additionally, it is recommended to implement mechanisms limiting the number of login attempts (rate limiting), account lockout after a specified number of failed attempts, and monitoring of suspicious activity on authentication API endpoints.

Who is affected

Apex Softcell LD Geo and Apex Softcell LD DP Back Office — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Apexsoftcell Ld Dp Back Office

    APP
    Apexsoftcell
    < 24.8.21.1
  • Apexsoftcell Ld Geo

    APP
    Apexsoftcell
    < 4.0.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-47085HIGH8.7same product

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters ...

CVE-2024-47086HIGH8.7same product

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation ...

CVE-2024-47087HIGH8.7same product

This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client...

CVE-2024-47089HIGH8.7same product

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID i...