5.3

CVE-2024-55198

Exploit
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CelkCelk Saude Version3.1.252.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-204 Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
Technical Description
https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55198
Third Party Advisory
Exploit