PT-2024-13168 · Veridium · Veridiumid
Lim Jing Qiang
·
Published
2024-04-03
·
Updated
2024-08-21
·
CVE-2023-44039
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
VeridiumID versions prior to 3.5.0
Description
The issue allows an internal unauthenticated attacker, who can pass enrollment verifications and is allowed to enroll a FIDO key, to register their FIDO authenticator to a victim's account, consequently taking over the account. This is related to the WebAuthn API.
Recommendations
For versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebAuthn API or limiting the ability to enroll new FIDO keys to prevent potential account takeovers.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veridiumid