CVE-2024-54454

MEDIUM

Kurmi Provisioning Suite <7.9.0.35, 7.10.x-7.10.0.18, 7.11.x-7.11.0...

Title source: llm
STIX 2.1

Description

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.

References (2)

Core 2
Core References
Various Sources
https://kurmi-software.com

Scores

CVSS v3 5.3
EPSS 0.0036
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-203
Status published
Published Dec 27, 2024
Tracked Since Feb 18, 2026