PT-2024-34705 · Aero · Aero

Mohit Gadiya

·

Published

2024-11-04

·

Updated

2024-11-06

·

CVE-2024-51561

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Aero (affected versions not specified)
Description This issue exists due to improper implementation of the OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this by intercepting and manipulating responses during the second factor authentication process. Successful exploitation could allow the attacker to bypass OTP verification for accessing other user accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-51561

Affected Products

Aero