The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.
References
Configurations
No configuration.
History
31 Dec 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-31 02:15
Updated : 2024-12-31 02:15
NVD link : CVE-2024-12839
Mitre link : CVE-2024-12839
CVE.ORG link : CVE-2024-12839
JSON object : View
Products Affected
No product.
CWE
CWE-294
Authentication Bypass by Capture-replay