Reedos develops the AIM-Star application, a niche product where the observed vulnerability surface centers on authorization and authentication handling, including user-controlled key authorization bypasses, authentication-attempt rate limiting, and exposure of private personal information. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reedos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45790CRITICAL This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could | Sep 11, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-45788HIGH This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit thi | Sep 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45787MEDIUM This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker cou | Sep 11, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-45786MEDIUM This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnera | Sep 11, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-45789MEDIUM This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authentic | Sep 11, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reedos.
Media articles that mention a CVE ID that affects a product developed by Reedos — matched by CVE ID, not by vendor name.