This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts.
History

Wed, 23 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 11:00:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts. This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts.

Wed, 23 Apr 2025 10:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts.
Title Brute Force Attack Vulnerability in Meon KYC solutions
Weaknesses CWE-307
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2025-04-23T10:25:16.725Z

Updated: 2025-04-23T15:29:56.184Z

Reserved: 2025-04-16T12:00:23.726Z

Link: CVE-2025-42600

cve-icon Vulnrichment

Updated: 2025-04-23T15:29:51.592Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T11:15:46.603

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-42600

cve-icon Redhat

No data.