Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61482

Опубликовано: 27 окт. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

EPSS

Процентиль: 5%
0.00021
Низкий

7.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.2
github
3 месяца назад

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

EPSS

Процентиль: 5%
0.00021
Низкий

7.2 High

CVSS3

Дефекты

CWE-200