CRITICAL🇵🇱 Wersja polska

CVE-2024-51561

CVSS 9.3v4.0pub. 2024-11-04upd. 2024-11-06

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.

🤖 AI Analysis
How it works

The vulnerability stems from improper implementation of the OTP validation mechanism in specific API endpoints. An authenticated attacker remotely intercepts and manipulates responses exchanged during the second factor authentication process. By appropriately modifying these responses, it is possible to bypass OTP verification without knowledge of the correct one-time code.

Impact

An attacker can gain unauthorized access to other users' accounts by bypassing two-factor authentication protection. This results in complete takeover of the victim's account along with access to their data and system functions.

Mitigation & patch

Patches available from the vendor should be applied according to the references (https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0332). Until updates are applied, it is recommended to monitor API traffic for manipulation of authentication responses and consider temporarily restricting access to vulnerable endpoints.

Who is affected

63Moons Aero and 63Moons Wave 2.0 — specific versions indicated in vendor references (CERT-In CIVN-2024-0332)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • 63moons Aero

    APP
    63Moons
    < 120820241550
  • 63moons Wave 2.0

    APP
    63Moons
    < 1.1.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-51558CRITICAL9.3PL ✓same product

Brak ograniczeń liczby prób logowania w Wave 2.0 (brute force)

CVE-2024-51556HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API...

CVE-2024-51557HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An ...

CVE-2024-51559HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An au...

CVE-2024-51560HIGH7.1same product

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API...