This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
History

Thu, 13 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 11:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
Title No Rate Limiting Vulnerability in CAP back office application
Weaknesses CWE-799
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2025-03-13T19:33:09.748Z

Reserved: 2025-03-13T06:38:16.283Z

Link: CVE-2025-29998

cve-icon Vulnrichment

Updated: 2025-03-13T19:33:05.914Z

cve-icon NVD

Status : Received

Published: 2025-03-13T12:15:14.277

Modified: 2025-03-13T12:15:14.277

Link: CVE-2025-29998

cve-icon Redhat

No data.