CVE-2024-39340
Status: DeferredHigh (8.8)—
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview 12.7.0. The issue has been fixed in UTM 12.6.5 and 12.7.1.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.91%
- Percentile among all scored CVEs: 59
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-287
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-39340",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-39340",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-16T18:44:21.554486Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:securepoint:unified_threat_management:*:*:*:*:*:*:*:*"
],
"vendor": "securepoint",
"product": "unified_threat_management",
"versions": [
{
"status": "affected",
"version": "11.5",
"lessThan": "12.6.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "12.7.0",
"lessThan": "12.7.1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-07-12T13:15:12.057",
"references": [
{
"url": "https://wiki.securepoint.de/Advisory/CVE-2024-39340",
"source": "cve@mitre.org"
},
{
"url": "https://wiki.securepoint.de/UTM/Changelog",
"source": "cve@mitre.org"
},
{
"url": "https://www.securepoint.de/en/for-companies/utm-firewall",
"source": "cve@mitre.org"
},
{
"url": "https://wiki.securepoint.de/UTM/Changelog",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.securepoint.de/en/for-companies/utm-firewall",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview 12.7.0. The issue has been fixed in UTM 12.6.5 and 12.7.1."
},
{
"lang": "es",
"value": "Securepoint UTM anterior a 12.6.5 maneja mal los códigos OTP."
}
],
"lastModified": "2026-06-17T07:41:45.103",
"sourceIdentifier": "cve@mitre.org"
}