CVE-2024-54454

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Dec 31, 2024
CWE ID 203

Summary

CVE-2024-54454 is a newly disclosed vulnerability affecting the Kurmi Provisioning Suite before versions 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. This issue involves an Observable Response Discrepancy in the "sendPasswordReinitLink" action of the "unlogged.do" page. Attackers can exploit this flaw to test the validity of usernames, confirming their accuracy remotely. This may pose a security risk if an attacker can gain access to sensitive user information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share