Vulnerabilities > Reedos

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-45790 Improper Restriction of Excessive Authentication Attempts vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login.
network
low complexity
reedos CWE-307
critical
9.8
2024-09-11 CVE-2024-45786 Authorization Bypass Through User-Controlled Key vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints.
network
low complexity
reedos CWE-639
6.5
2024-09-11 CVE-2024-45787 Unspecified vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints.
network
low complexity
reedos
6.5
2024-09-11 CVE-2024-45788 Unspecified vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints.
network
low complexity
reedos
7.5
2024-09-11 CVE-2024-45789 Improper Validation of Integrity Check Value vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process.
network
low complexity
reedos CWE-354
4.3