Vulnerability Description
RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Identityautomation | Rapididentity | <= 2023.0.2 |
Related Weaknesses (CWE)
References
- https://benrogozinski.github.io/CVE-2024-45589/ExploitThird Party Advisory
- https://help.rapididentity.com/docs/rapididentity-lts-release-notesRelease Notes
FAQ
What is CVE-2024-45589?
CVE-2024-45589 is a vulnerability with a CVSS score of 5.9 (MEDIUM). RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username paramet...
How severe is CVE-2024-45589?
CVE-2024-45589 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45589?
Check the references section above for vendor advisories and patch information. Affected products include: Identityautomation Rapididentity.