peter bassill · operator
$ cve CVE-2024-39891 JSON

CVE-2024-39891 KEV

5.3
MEDIUM · CVSS 3.1 · EPSS 1.7% (pctl 76)

Patch first

On CISA KEV — known exploited in the wild, due 2024-08-13.

Description

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS1.67% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-203
On CISA KEVyes — remediate by 2024-08-13
Public exploitnone known
Published2024-07-02
Last modified2026-06-17

CISA KEV

NameTwilio Authy Information Disclosure Vulnerability
Added2024-07-23
Due2024-08-13
Vendor / productTwilio / Authy
Ransomware usenone reported

Affected (2)

VendorProduct
twilioauthy
twilioauthy authenticator

References

→ the Explorer  ·  watch your stack  ·  NVD