63Moons Aero vulnerabilities
6 known vulnerabilities affecting 63moons/aero.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2024-51558P2CRITICALCVSS 9.8fixed in 1208202415502024-11-04
CVE-2024-51558 [CRITICAL] CWE-307 CVE-2024-51558: This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentic
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accoun
nvd
CVE-2024-51561P3HIGHCVSS 7.5fixed in 1208202415502024-11-04
CVE-2024-51561 [HIGH] CWE-807 CVE-2024-51561: This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in cert
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process.
Successful exploitation of this vulnerability could allow the
nvd
CVE-2024-51559P3MEDIUMCVSS 6.5fixed in 1208202415502024-11-04
CVE-2024-51559 [MEDIUM] CWE-639 CVE-2024-51559: This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoi
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
nvd
CVE-2024-51557P3MEDIUMCVSS 6.5fixed in 1208202415502024-11-04
CVE-2024-51557 [MEDIUM] CWE-799 CVE-2024-51557: This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API end
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
nvd
CVE-2024-51556P3MEDIUMCVSS 6.5fixed in 1208202415502024-11-04
CVE-2024-51556 [MEDIUM] CWE-327 CVE-2024-51556: This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.
nvd
CVE-2024-51560P4MEDIUMCVSS 4.3fixed in 1208202415502024-11-04
CVE-2024-51560 [MEDIUM] CWE-209 CVE-2024-51560: This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at c
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system
nvd