PT-2024-32400 · Apex Softcell · Apex Softcell Ld Dp Back Office

Mohit Gadiya

·

Published

2024-09-18

·

Updated

2024-09-26

·

CVE-2024-47086

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apex Softcell LD DP Back Office (affected versions not specified)
Description This issue is related to the improper implementation of the OTP validation mechanism in certain API endpoints, allowing an authenticated remote attacker to exploit the vulnerability by providing an arbitrary OTP value for authentication. This could enable the attacker to bypass OTP verification for other user accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-47086

Affected Products

Apex Softcell Ld Dp Back Office