6.3
CVE-2024-4846
- EPSS 0.09%
- Veröffentlicht 25.06.2024 13:15:50
- Zuletzt bearbeitet 28.03.2025 16:22:26
- Quelle security@devolutions.net
- CVE-Watchlists
- Unerledigt
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Devolutions Server Version < 2024.1.15.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.264 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.