PT-2024-33481 · Zimaos · Zimaos

Drdark1999

·

Published

2024-10-24

·

Updated

2024-11-06

·

CVE-2024-49358

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZimaOS versions 1.2.4 and earlier
Description The issue concerns the API endpoint http://<Server-IP>/v1/users/login, which returns distinct responses based on whether a username exists or the password is incorrect. This behavior can be exploited for username enumeration, allowing attackers to determine whether a user exists in the system or not. Attackers can leverage this information in further attacks, such as credential stuffing or targeted password brute-forcing.
Recommendations For ZimaOS versions 1.2.4 and earlier, as a temporary workaround, consider restricting access to the http://<Server-IP>/v1/users/login API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-49358
GHSA-3F6G-8R88-3MX5

Affected Products

Zimaos