📦 Wave 2.0

by 63moons

🔍 What is Wave 2.0?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51558

CRITICAL CVSS 9.8 Nov 4, 2024

This vulnerability allows remote attackers to bypass authentication protections in Wave 2.0 by brute-forcing OTP, MPIN, or password credentials due to missing rate limiting. Any organization using Wav...

CVE-2024-51561

HIGH CVSS 7.5 Nov 4, 2024

This vulnerability allows authenticated attackers to bypass OTP verification in Aero's authentication system by intercepting and manipulating responses during second-factor authentication. It affects ...

CVE-2024-51557

MEDIUM CVSS 6.5 Nov 4, 2024

This vulnerability allows authenticated attackers to send unlimited OTP requests through a vulnerable API endpoint in Wave 2.0, causing OTP bombing/flooding attacks. This affects systems running Wave ...

CVE-2024-51560

MEDIUM CVSS 4.3 Nov 4, 2024

This vulnerability in Wave 2.0 allows authenticated attackers to trigger error messages containing sensitive information by sending invalid inputs to a specific API endpoint. The information disclosur...