PT-2024-34700 · Wave · Wave
Mohit Gadiya
·
Published
2024-11-04
·
Updated
2024-11-08
·
CVE-2024-51557
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wave 2.0
Description
This issue exists due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this by sending multiple OTP requests through the vulnerable API endpoint, leading to OTP bombing or flooding on the targeted system. The vulnerability is related to improper control of interaction frequency.
Recommendations
For Wave 2.0, patch to the latest version as soon as possible and monitor for suspicious activity. As a temporary workaround, consider restricting access to the vulnerable API endpoint to minimize the risk of exploitation.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wave