CVE-2024-6832Medium· 5.9▾ SunlitThe account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repe…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.
When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence.
api_control_plane = 4.5.0api_control_plane = 4.6.0api_manager = 3.1.0api_manager = 3.2.0api_manager = 3.2.1api_manager = 4.1.0api_manager = 4.2.0api_manager = 4.3.0api_manager = 4.4.0api_manager = 4.5.0api_manager = 4.6.0identity_server = 5.10.0identity_server = 5.11.0identity_server = 6.0.0identity_server = 6.1.0identity_server = 7.0.0identity_server_as_key_manager = 5.10.0open_banking_am = 2.0.0open_banking_iam = 2.0.0traffic_manager = 4.5.0traffic_manager = 4.6.0universal_gateway = 4.5.0universal_gateway = 4.6.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input
CVE-2024-10302Medium· 4.0The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
CVE-2026-39452High· 7.3Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege
CVE-2019-1970Medium· 5.8A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file po…
CVE-2019-1669High· 8.6A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) cond…