Количество 3
Количество 3
CVE-2024-39340
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview 12.7.0. The issue has been fixed in UTM 12.6.5 and 12.7.1.
GHSA-vc4m-x7gg-xqpc
Securepoint UTM before 12.6.5 mishandles OTP codes.
BDU:2024-05986
Уязвимость функции OTP (One-Time Password) микропрограммного обеспечения межсетевых экранов Securepoint Unified Threat Management (UTM), позволяющая нарушителю обойти двухфакторную проверку
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-39340 The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview 12.7.0. The issue has been fixed in UTM 12.6.5 and 12.7.1. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-vc4m-x7gg-xqpc Securepoint UTM before 12.6.5 mishandles OTP codes. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
BDU:2024-05986 Уязвимость функции OTP (One-Time Password) микропрограммного обеспечения межсетевых экранов Securepoint Unified Threat Management (UTM), позволяющая нарушителю обойти двухфакторную проверку | CVSS3: 8.8 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу