CVE-2024-45790
- EPSS 0.83%
- Veröffentlicht 11.09.2024 13:15:03
- Zuletzt bearbeitet 18.09.2024 18:38:04
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against ...
CVE-2024-45787
- EPSS 0.15%
- Veröffentlicht 11.09.2024 12:15:02
- Zuletzt bearbeitet 18.09.2024 18:15:07
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API ...
CVE-2024-45788
- EPSS 0.49%
- Veröffentlicht 11.09.2024 12:15:02
- Zuletzt bearbeitet 18.09.2024 19:57:10
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API...
CVE-2024-45789
- EPSS 0.05%
- Veröffentlicht 11.09.2024 12:15:02
- Zuletzt bearbeitet 18.09.2024 19:55:58
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating ...
CVE-2024-45786
- EPSS 0.14%
- Veröffentlicht 11.09.2024 12:15:01
- Zuletzt bearbeitet 18.09.2024 20:12:47
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could...