VYPR
Medium severity4.3NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026

CVE-2022-34772

CVE-2022-34772

Description

Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting.

Affected products

3
  • Tabit/Tabit3 versions
    cpe:2.3:a:tabit:tabit:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:tabit:tabit:*:*:*:*:*:*:*:*range: <3.27.0
    • (no CPE)range: 3.27.0
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.