CVE-2022-45168

June 10, 2024, 6:06 p.m.

None
No Score

Description

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the TOTP.

Product(s) Impacted

Product Versions
LIVEBOX Collaboration vDesk
  • ['through v018']

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: June 10, 2024, 3:15 p.m.
Last Modified: June 10, 2024, 6:06 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.