CVE Feed

    Dashboard / CVE / CVE-2024-42164

    CVE-2024-42164

    Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.

    Published:Aug 12, 2024
    Last Modified:Aug 29, 2024
    EPS:Aug 12, 2024
    EPSS Score:0.00106
    CVSS Score:4.3

    Affected Products

    Vendor
    Fiware
    Product
    Keyrock

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High