6.5
CVE-2025-43798
- EPSS 0.05%
- Veröffentlicht 15.09.2025 20:53:02
- Zuletzt bearbeitet 16.12.2025 16:36:29
- Quelle security@liferay.com
- CVE-Watchlists
- Unerledigt
Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version >= 2023.q3.1 < 2023.q3.5
Liferay ≫ Digital Experience Platform Version7.3 Update-
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate16
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate17
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate18
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate19
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate20
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate21
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate22
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate23
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate24
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate25
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate26
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate27
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate28
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate29
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate30
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate31
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate32
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate33
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate34
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate35
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate9
Liferay ≫ Digital Experience Platform Version7.4
Liferay ≫ Digital Experience Platform Version2023.q4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.161 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| security@liferay.com | 2.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-304 Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.