PT-2022-16290 · Devolutions · Devolutions Password Hub

Sven Halm

·

Published

2022-03-03

·

Updated

2023-08-08

·

CVE-2022-23849

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Password Hub for iOS versions prior to 2021.3.4
Description The biometric lock in the application allows attackers to access it due to an authentication bypass issue. This can be exploited by rapidly making failed biometric authentication attempts.
Recommendations For versions prior to 2021.3.4, update to version 2021.3.4 or later to resolve the issue. As a temporary workaround, consider disabling the biometric lock feature until a patch is applied. Restrict access to sensitive data stored in the application to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-23849

Affected Products

Devolutions Password Hub