← voltar
CVE-2024-45394

Secret encryption vulnerable to brute-force attacks

CVSS 8.8 HIGHEPSS 0.1%CWE-261CWE-327
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.8EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 set 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →