CyberRota Analysis
AI-GeneratedWazuh versions from 4.0.0 to 4.14.6 and 5.0.0-beta2 are vulnerable to a timing attack that allows unauthenticated remote attackers to enumerate valid usernames by exploiting the differing response times of the authentication process. This vulnerability can lead to credential stuffing or targeted attacks against valid accounts. Organizations using affected versions should prioritize upgrading to the patched releases to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs check_password_hash() only when the supplied username exists. A nonexistent username returns immediately, while a valid username causes an expensive bcrypt calculation. An unauthenticated remote attacker can compare authentication response times to enumerate valid Wazuh usernames and use that information in subsequent credential attacks. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.