← Back

CVE-2024-0391

nvd nist
Published: May 11, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks. Attackers can leverage this information to craft targeted phishing campaigns or other malicious activities aimed at tricking users into divulging sensitive data, potentially damaging the organization's reputation and leading to regulatory non-compliance and financial consequences.

Affected (7)

3 products
Identity Server
Identity Server As Key Manager
Open Banking Iam
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 5.10.0 to 5.10.0.379
From 5.11.0 to 5.11.0.426
From 6.0.0 to 6.0.0.253
From 6.1.0 to 6.1.0.254
From 7.0.0 to 7.0.0.131
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.10.0 to 5.10.267
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.0.0.318

References (1)

Timeline

No history available yet.