Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6q6r-cf26-j7gh

Опубликовано: 08 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.

EPSS

Процентиль: 9%
0.00031
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 4.6
nvd
5 месяцев назад

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response. NOTE: this is disputed by the Supplier because, by design, the product successfully authenticates a client that possesses a cookie whose validity time interval includes the current time, and thus authentication after any type of "interception" is not a violation of the security model. (The cookie has the HttpOnly attribute.)

EPSS

Процентиль: 9%
0.00031
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-290