
Tata B2B Platform Flaw Lets Attackers Bypass OTP and Take Over Accounts
Tata Nexarc has fixed a critical authentication flaw that exposed login one-time passwords (OTPs) in client-visible API responses. The issue could have allowed an unauthenticated attacker who knows a registered mobile number to obtain the OTP required for passwordless login and seize the account. Eaton reported the vulnerability to the Indian Computer Emergency Response Team […]
The post Tata B2B Platform Flaw Lets Attackers Bypass OTP and Take Over Accounts appeared first on Cyber Security News.