CVE-2024-51557

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:63moons:aero:*:*:*:*:*:*:*:*
cpe:2.3:a:63moons:wave_2.0:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-04 13:17

Updated : 2024-11-08 15:19


NVD link : CVE-2024-51557

Mitre link : CVE-2024-51557

CVE.ORG link : CVE-2024-51557


JSON object : View

Products Affected

63moons

  • wave_2.0
  • aero
CWE
CWE-799

Improper Control of Interaction Frequency

CWE-770

Allocation of Resources Without Limits or Throttling