PT-2024-20548 · Vantage6 · Vantage6

Bartvanb

·

Published

2024-01-30

·

Updated

2026-01-16

·

CVE-2024-24770

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions vantage6 (affected versions not specified)
Description The issue allows attackers to determine which usernames exist in vantage6 by calling the API routes "/recover/lost" and "/2fa/lost", which send emails to users if they have lost their password or MFA token. Usernames can be found by assessing response time differences, and additionally, they can be found because the endpoint gives a response "Failed to login" if the username exists. This could aid attackers in credential attacks.
Recommendations As a temporary workaround, consider restricting access to the API routes "/recover/lost" and "/2fa/lost" until a patch is available. Upgrade to a new release as soon as it is available, as the issue has been addressed in commit aecfd6d0e and is expected to ship in subsequent releases.

Exploit

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24770
GHSA-45GQ-Q4XH-CP53
GHSA-5H3X-6GWF-73JM

Affected Products

Vantage6