PT-2024-17757 · Cgfido · Cgfido

周詳

·

Published

2024-12-31

·

Updated

2025-01-05

·

CVE-2024-12838

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CGFIDO (affected versions not specified)
Description The passwordless login mechanism in CGFIDO has an Authentication Bypass issue, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators. This enables attackers to compromise security protocols.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-12838

Affected Products

Cgfido