This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.
The application does not implement restrictions on the number of failed login attempts (CWE-307) on API endpoints handling OTP authentication. An attacker can automatically send successive login requests, systematically checking possible OTP values. Due to the limited range of typical OTP code values, the attack can succeed in a short time. No permissions or victim interaction are required.
An attacker can gain unauthorized access to accounts of other system users. This results in a breach of confidentiality and integrity of data available in the context of compromised accounts.
Apply patches available from the vendor according to the references. Additionally, it is recommended to implement mechanisms limiting the number of login attempts (rate limiting), account lockout after a specified number of failed attempts, and monitoring of suspicious activity on authentication API endpoints.
Apex Softcell LD Geo and Apex Softcell LD DP Back Office — versions indicated in vendor references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XApexsoftcell Ld Dp Back Office
APPApexsoftcell< 24.8.21.1Apexsoftcell Ld Geo
APPApexsoftcell< 4.0.0.7
Related vulnerabilities
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters ...
This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation ...
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client...
This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID i...