The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators.
Solution:
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-8332-2100f-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-8333-32cf8-2.html | third party advisory |