This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Apr 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-23 11:15
Updated : 2025-04-23 14:08
NVD link : CVE-2025-42600
Mitre link : CVE-2025-42600
CVE.ORG link : CVE-2025-42600
JSON object : View
Products Affected
No product.
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts