{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-24T08:37:54.339","vulnerabilities":[{"cve":{"id":"CVE-2022-34772","sourceIdentifier":"cna@cyber.gov.il","published":"2022-08-22T15:15:16.193","lastModified":"2024-11-21T07:10:09.323","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting."},{"lang":"es","value":"Tabit - enumeración de contraseñas. Descripción: Tabit - enumeración de contraseñas. Las contraseñas para el sistema Tabit es una OTP de 4 dígitos. Uno puede reenviar la OTP e intentar iniciar sesión indefinidamente. Una vez más, este es un ejemplo de OWASP: API4 - Limitación de velocidad."}],"metrics":{"cvssMetricV31":[{"source":"cna@cyber.gov.il","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.9,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-521"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tabit:tabit:*:*:*:*:*:*:*:*","versionEndExcluding":"3.27.0","matchCriteriaId":"1D2DB843-28A9-4524-B84D-F714BF3DB9F6"}]}]}],"references":[{"url":"https://www.gov.il/en/departments/faq/cve_advisories","source":"cna@cyber.gov.il","tags":["Third Party Advisory"]},{"url":"https://www.gov.il/en/departments/faq/cve_advisories","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}