CVE-2024-8122: Potential brute force vulnerability due to non-expiring SMS OTPs
The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP.
The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Affected Software
Event History
Frequently Asked Questions
Are deployments affected if no SMS OTP expiration has been configured explicitly?
The issue is the failure to enforce a default expiration time for SMS OTPs. Unused OTPs can therefore remain valid indefinitely when an expiry is not otherwise enforced.
What does an attacker need to exploit this issue?
An attacker needs to repeatedly guess a valid, unused SMS OTP. The CVSS vector indicates the attack can be performed over the network without privileges or user interaction, although exploitation has high attack complexity.
What is the potential impact of a successful attack?
Successfully guessing the OTP can bypass MFA and allow unauthorized takeover of the affected user's account. This can compromise the security and privacy of the user and the system.