PT-2022-11693 · Veridium · Veridiumid Veridiumad

Philipp Mao

·

Published

2022-01-28

·

Updated

2022-02-02

·

CVE-2021-42791

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions VeridiumID VeridiumAD version 2.5.3.0
Description An issue was discovered in the HTTP request that triggers push notifications for enrolled users, where proper access control is not enforced. This allows a user to trigger push notifications for any other user and modify the text contained in the notification. If the recipient accepts the notification, the user who triggered it can obtain the recipient's login certificate.
Recommendations For VeridiumID VeridiumAD version 2.5.3.0, consider disabling the push notification feature until a patch is available to enforce proper access control and prevent unauthorized modifications to notification text. Restrict access to the HTTP request endpoint that triggers push notifications to minimize the risk of exploitation. Avoid using the feature that allows triggering push notifications for other users until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42791

Affected Products

Veridiumid Veridiumad