PT-2022-25406 · Nps · Nps

Published

2022-10-06

·

Updated

2022-10-13

·

CVE-2022-40494

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NPS versions prior to 0.26.10
Description The issue allows for an authentication bypass via constantly generating and sending the Auth key and Timestamp parameters.
Recommendations For versions prior to 0.26.10, update to version 0.26.10 or later to resolve the issue. As a temporary workaround, consider restricting access to authentication endpoints to minimize the risk of exploitation. Avoid using the Auth key and Timestamp parameters in authentication requests until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-40494

Affected Products

Nps