Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c45v-xc5j-qr2x

Опубликовано: 31 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

EPSS

Процентиль: 68%
0.00558
Низкий

8.8 High

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

EPSS

Процентиль: 68%
0.00558
Низкий

8.8 High

CVSS3

Дефекты

CWE-294