CVE-2024-24769Low▾ SunlitVantage6: No limit on emails sent for password/MFA reset
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Users can reset their MFA token via API routes that send them an email. Currently the number of emails that is sent is not limited. This gives attackers the option to flood someones mailbox with a lot of emails, and would have adverse effects on the SMTP server which may be seen as spam sender.
Note resetting the MFA token requires a correct password, so the potential impact for this is very low.
No
No
vantage6 < 5.0.0Upgrade to a patched release:
vantage6 5.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration