CVE-2024-39398: OTP 2FA can be bruteforced
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to perform brute force attacks and potentially gain unauthorized access to accounts. Exploitation of this issue does not require user interaction, but attack complexity is high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39398?
The severity of CVE-2024-39398 is considered medium, as it allows for excessive authentication attempts leading to potential brute force attacks.
How do I fix CVE-2024-39398?
To fix CVE-2024-39398, update Adobe Commerce to version 2.4.4-p10 or later, 2.4.5-p9 or later, or 2.4.6-p7 or later.
Which Adobe Commerce versions are affected by CVE-2024-39398?
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by CVE-2024-39398.
What type of vulnerability is CVE-2024-39398?
CVE-2024-39398 is categorized as an Improper Restriction of Excessive Authentication Attempts vulnerability.
Can CVE-2024-39398 lead to security feature bypass?
Yes, CVE-2024-39398 can potentially allow an attacker to bypass security features through brute force attempts.