Threat Advisory

Apex Softcell Flaws Could Lead to Unauthorized Transactions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Security vulnerability has issued a warning regarding five high-severity vulnerabilities in Apex Softcell's mobile stock trading and back-office platforms. Affected versions include Apex Softcell LD Geo prior to and LD DP Back Office. These vulnerabilities could allow remote attackers to perform user enumeration, bypass OTP verification, manipulate unauthorized transactions, and gain access to sensitive user information. Users are strongly advised to upgrade to the latest versions to mitigate the risks associated with these vulnerabilities and ensure the security of sensitive financial data and trading operations. Timely updates are crucial for maintaining system integrity, as attackers could exploit these flaws for malicious purposes. Proactive measures must be taken to safeguard user accounts and protect financial transactions from unauthorized access.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Security vulnerability has issued a warning regarding five high-severity vulnerabilities in Apex Softcell's mobile stock trading and back-office platforms. Affected versions include Apex Softcell LD Geo prior to and LD DP Back Office. These vulnerabilities could allow remote attackers to perform user enumeration, bypass OTP verification, manipulate unauthorized transactions, and gain access to sensitive user information. Users are strongly advised to upgrade to the latest versions to mitigate the risks associated with these vulnerabilities and ensure the security of sensitive financial data and trading operations. Timely updates are crucial for maintaining system integrity, as attackers could exploit these flaws for malicious purposes. Proactive measures must be taken to safeguard user accounts and protect financial transactions from unauthorized access.[emaillocker id="1283"]

 

  • CVE-2024-47085: This vulnerability exists in the LD DP Back Office due to improper validation of the parameters “cCdslClicentcode” and “cLdClientCode” in the API endpoint. Authenticated remote attackers could exploit this vulnerability by manipulating parameters in the API request body, leading to the exposure of sensitive information belonging to other users.

 

  • CVE-2024-47086: This vulnerability, also found in the LD DP Back Office, arises from improper implementation of an OTP validation mechanism in certain API endpoints. Authenticated remote attackers could exploit this by providing arbitrary OTP values for authentication, allowing them to change the API response and bypass OTP verification for other user accounts.

 

  • CVE-2024-47087: This vulnerability in LD Geo is caused by improper validation of specific parameters (Client ID, DPID, or BOID) in the API endpoint. Authenticated remote attackers could exploit this vulnerability by manipulating parameters in the API request body, leading to the exposure of sensitive information.

 

  • CVE-2024-47088: This vulnerability in LD Geo is created by missing restrictions on excessive failed authentication attempts on its API-based login. Remote attackers could exploit this by conducting brute force attacks on OTPs, potentially gaining unauthorized access to other user accounts.

 

  • CVE-2024-47089: This LD Geo vulnerability is due to improper validation of the transaction token ID in the API endpoint. Authenticated remote attackers could exploit this by manipulating the transaction token ID in the API request, resulting in unauthorized access to and modification of transactions belonging to other users.

RECOMMENDATION:

  • We strongly recommend you update Apex Softcell LD Geo to version 4.0.0.7 and LD DP Back Office to version 24.8.21.1.

REFERENCES:

The following reports contain further technical details:
https://cyble.com/blog/apex-softcell-flaws-could-lead-to-unauthorized-transactions-cert-in-warns/

[/emaillocker]
crossmenu