PT-2022-16290 · Devolutions · Devolutions Password Hub

·

CVE-2022-23849

·

Published

2022-03-03

·

Updated

2023-08-08

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Password Hub for iOS versions prior to 2021.3.4
Description The biometric lock in the application allows attackers to access it due to an authentication bypass issue. This can be exploited by rapidly making failed biometric authentication attempts.
Recommendations For versions prior to 2021.3.4, update to version 2021.3.4 or later to resolve the issue. As a temporary workaround, consider disabling the biometric lock feature until a patch is applied. Restrict access to sensitive data stored in the application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-23849

Affected Products

Devolutions Password Hub