CVE-2022-34771
Last modified
CVE-2022-34771 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits behalf to anyone registered on the system - the API receives the parameters: phone number, and CustomMessage, We can use that API to craft malicious messages to any user of the system. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits behalf to anyone registered on the system - the API receives the parameters: phone number, and CustomMessage, We can use that API to craft malicious messages to any user of the system. In addition, the API probably has some kind of template injection potential. When entering {{OTP}} in the custom message field it is formatted into an OTP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tabit | Tabit | < 3.27.0 |
References
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34771?
How severe is CVE-2022-34771?
How do I fix CVE-2022-34771?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34765A CWE-73: External Control of File Name or Path vulnerabilit…5.3
- CVE-2022-34767Web page which "wizardpwd.asp" ALLNET Router model WR0500AC …9.8
- CVE-2022-34768insert HTML / js code inside input how to get to the vulnera…7.5
- CVE-2022-34769Michlol - rashim web interface Insecure direct object refere…5.5
- CVE-2022-3477The tagDiv Composer WordPress plugin before 3.5, required by…9.8
- CVE-2022-34770Tabit - sensitive information disclosure. Several APIs on th…7.5
- CVE-2022-34772Tabit - password enumeration. Description: Tabit - password …8.8
- CVE-2022-34773Tabit - HTTP Method manipulation. https://bridge.tabit.cloud…9.8
- CVE-2022-34774Tabit - Arbitrary account modification. One of the endpoints…5.3
- CVE-2022-34775Tabit - Excessive data exposure. Another endpoint mapped by …7.5
- CVE-2022-34776Tabit - giftcard stealth. Several APIs on the web system dis…7.5
- CVE-2022-34777Jenkins GitLab Plugin 1.5.34 and earlier does not escape mul…5.4
Are you affected by CVE-2022-34771?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
