V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2024-57610
CVE
HighConfirmedExploit available

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly…

CVSS
7.5
High
EPSS
0.10
p93
Published
2024-01-01
Updated
2024-01-01
Description

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.

Tags · CWE
Pre-auth
CWE-307
CAPEC-16
CAPEC-49
CAPEC-560
CAPEC-565
CAPEC-600
CAPEC-652
CAPEC-653
Affected products
Sylius
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.098 · p93
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-560 · CWE-307
└ via CAPEC-49 · CWE-307
└ via CAPEC-565 · CWE-307
└ via CAPEC-600 · CWE-307
└ via CAPEC-652 · CWE-307
Known exploits — Сканер-ВС
CVE-2024-57610
github-poc · https://github.com/Mr-UN533N/CVE-2024-57610
Enterprise
Affected software
ProductVendorStatus
sylius*Tracked
Source databases
CVE