Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12839

Опубликовано: 31 дек. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

EPSS

Процентиль: 68%
0.00558
Низкий

8.8 High

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 8.8
github
около 1 года назад

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

EPSS

Процентиль: 68%
0.00558
Низкий

8.8 High

CVSS3

Дефекты

CWE-294