Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-8122— Potential brute force vulnerability due to non-expiring SMS OTPs

Quick assessment

Affected
WSO2 WSO2 Identity Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WSO2 身份服务器未对多因素认证(MFA)中使用的短信一次性密码(OTP)强制执行默认的过期时间。这导致未使用的 OTP 可以无限期保持有效,从而为攻击者通过反复猜测 OTP 实施暴力破解攻击提供了可乘之机。 由于 OTP 缺乏自动过期机制,攻击者拥有无限的时间窗口来尝试猜解正确的验证码。一旦暴力破解攻击成功,即可绕过 MFA 防护,导致攻击者非法接管用户账户,进而危及个人及系统的隐私与安全。

CVSS 5.9 · Medium EPSS 0.25% · P16

Affected Version Matrix 4

VendorProduct Version RangeStatus
WSO2 WSO2 Identity Server < 5.11.0 unknown
5.11.0< 5.11.0.372 affected
6.0.0< 6.0.0.227 affected
6.1.0< 6.1.0.219 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-8122

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Potential brute force vulnerability due to non-expiring SMS OTPs
Source: CVE Program / CVE List V5
Vulnerability Description
The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP. The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WSO2 WSO2 Identity Server 5.11.0 ~ 5.11.0.372 -

II. Public POCs for CVE-2024-8122

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-8122

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-8122 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-8122

No comments yet


Leave a comment