CVE-2021-42791

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2022
Last modified:
02/02/2022

Description

An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in the push notification can also be modified. If a user who receives the notification accepts it, then the user who triggered the notification can obtain the accepting user's login certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:veridiumid:veridiumad:2.5.3.0:*:*:*:*:*:*:*