CVE-2024-51557

MEDIUM

Wave 2.0 - DoS

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

Scores

CVSS v3 6.5
EPSS 0.0123
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-799 CWE-770
Status published
Products (2)
63moons/aero < 120820241550
63moons/wave_2.0 < 1.1.7
Published Nov 04, 2024
Tracked Since Feb 18, 2026