2024-07-02 20:03:23 +00:00
{
"id" : "CVE-2024-39891" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-07-02T18:15:03.447" ,
2024-12-20 17:03:44 +00:00
"lastModified" : "2024-12-20T16:15:33.687" ,
"vulnStatus" : "Analyzed" ,
2024-07-02 20:03:23 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
2024-07-03 23:58:47 +00:00
"value" : "In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)"
2024-07-03 14:05:06 +00:00
} ,
{
"lang" : "es" ,
2024-08-11 02:03:12 +00:00
"value" : "En la API de Twilio Authy, a la que acced\u00edan Authy Android antes de la versi\u00f3n 25.1.0 y Authy iOS antes de la versi\u00f3n 26.1.0, un endpoint no autenticado proporcionaba acceso a determinados datos de n\u00fameros de tel\u00e9fono, como se explot\u00f3 en junio de 2024. En concreto, el endpoint aceptaba un flujo de solicitudes que conten\u00edan n\u00fameros de tel\u00e9fono y respond\u00eda con informaci\u00f3n sobre si cada n\u00famero de tel\u00e9fono estaba registrado en Authy. (Sin embargo, las cuentas de Authy no se vieron comprometidas)."
2024-07-02 20:03:23 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-07-24 16:03:13 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cve@mitre.org" ,
"type" : "Secondary" ,
2024-07-24 16:03:13 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2024-07-24 16:03:13 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-07-24 16:03:13 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
} ,
2024-07-02 20:03:23 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-07-02 20:03:23 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2024-07-02 20:03:23 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-07-02 20:03:23 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
}
]
} ,
2024-12-08 03:06:42 +00:00
"cisaExploitAdd" : "2024-07-23" ,
"cisaActionDue" : "2024-08-13" ,
"cisaRequiredAction" : "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable." ,
"cisaVulnerabilityName" : "Twilio Authy Information Disclosure Vulnerability" ,
2024-07-03 04:04:51 +00:00
"weaknesses" : [
2024-07-24 16:03:13 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-203"
}
]
} ,
2024-07-03 04:04:51 +00:00
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-203"
}
]
}
] ,
2024-07-24 16:03:13 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:twilio:authy:*:*:*:*:*:iphone_os:*:*" ,
"versionEndExcluding" : "26.1.0" ,
"matchCriteriaId" : "F645AEA3-6ACC-4386-ACA9-793E66DBF31E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:twilio:authy_authenticator:*:*:*:*:*:android:*:*" ,
"versionEndExcluding" : "25.1.0" ,
"matchCriteriaId" : "07B60ED3-2C9B-46F8-9B6C-1FFB46067D06"
}
]
}
]
}
] ,
2024-07-02 20:03:23 +00:00
"references" : [
{
"url" : "https://cwe.mitre.org/data/definitions/203.html" ,
2024-07-24 16:03:13 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Technical Description"
]
2024-07-02 20:03:23 +00:00
} ,
2024-07-03 23:58:47 +00:00
{
"url" : "https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/" ,
2024-07-24 16:03:13 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Press/Media Coverage"
]
2024-07-03 23:58:47 +00:00
} ,
2024-07-02 20:03:23 +00:00
{
"url" : "https://www.twilio.com/docs/usage/security/reporting-vulnerabilities" ,
2024-07-24 16:03:13 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Product"
]
2024-07-02 20:03:23 +00:00
} ,
{
"url" : "https://www.twilio.com/en-us/changelog" ,
2024-07-24 16:03:13 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Release Notes"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cwe.mitre.org/data/definitions/203.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Technical Description"
]
} ,
{
"url" : "https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Press/Media Coverage"
]
} ,
{
"url" : "https://www.twilio.com/docs/usage/security/reporting-vulnerabilities" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Product"
]
} ,
{
"url" : "https://www.twilio.com/en-us/changelog" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Release Notes"
]
2024-07-02 20:03:23 +00:00
}
]
}