CVE-2023-44039
EUVD-2023-4839803.04.2024, 16:15
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| veridiumid | veridiumad | 𝑥 < 3.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References