Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rj69-qp3g-r76j

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

EPSS

Процентиль: 5%
0.00021
Низкий

7.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

EPSS

Процентиль: 5%
0.00021
Низкий

7.2 High

CVSS3

Дефекты

CWE-200