WSO2 身份服务器未对多因素认证(MFA)中使用的短信一次性密码(OTP)强制执行默认的过期时间。这导致未使用的 OTP 可以无限期保持有效,从而为攻击者通过反复猜测 OTP 实施暴力破解攻击提供了可乘之机。 由于 OTP 缺乏自动过期机制,攻击者拥有无限的时间窗口来尝试猜解正确的验证码。一旦暴力破解攻击成功,即可绕过 MFA 防护,导致攻击者非法接管用户账户,进而危及个人及系统的隐私与安全。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 Identity Server | < 5.11.0 |
unknown |
5.11.0< 5.11.0.372 |
affected | ||
6.0.0< 6.0.0.227 |
affected | ||
6.1.0< 6.1.0.219 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 Identity Server | 5.11.0 ~ 5.11.0.372 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet