CRITICAL🇵🇱 Wersja polska

CVE-2024-51558

CVSS 9.3v4.0pub. 2024-11-04upd. 2024-11-08

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.

🤖 AI Analysis
How it works

Wave 2.0 application does not implement restrictions on the number of failed authentication attempts on its API interface (CWE-307: Improper Restriction of Excessive Authentication Attempts). A remote attacker can repeatedly send login requests, trying successive combinations of OTP, MPIN, or password, without risk of being blocked or having additional security measures triggered. After guessing the correct authentication credentials, the attacker gains unauthorized access to the victim's account.

Impact

An attacker can gain unauthorized access to user accounts and take full control over them. The consequence is a breach of confidentiality, integrity, and availability of data stored on compromised accounts.

Mitigation & patch

Patches available from the vendor should be applied according to references. It is recommended to implement mechanisms limiting the number of login attempts (rate limiting, account lockout after a specified number of failed attempts) and monitoring of suspicious activity on the API interface.

Who is affected

63Moons Wave 2.0 and 63Moons Aero — specific versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • 63moons Aero

    APP
    63Moons
    < 120820241550
  • 63moons Wave 2.0

    APP
    63Moons
    < 1.1.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-51561CRITICAL9.3PL ✓same product

Obejście weryfikacji OTP w produktach 63Moons Aero i Wave 2.0

CVE-2024-51556HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API...

CVE-2024-51557HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An ...

CVE-2024-51559HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An au...

CVE-2024-51560HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API...