216.73.216.233

CVE-2024-45394

· Published 03/09/2024 21:15 · Modified 09/10/2024 15:15

Labels: CVE-2024-45394 2024-09-03CVE-2024-45394CWE-261CWE-326[email protected]

Essential information

Published
03/09/2024 21:15
Modified
09/10/2024 15:15
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
authenticator / authenticator cpe:2.3:a:authenticator:authenticator:*:*:*:*:*:*:*:*

References