CVE-2023-44039

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2024
Last modified:
16/04/2025

Description

In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:* 3.5.0 (excluding)