CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-44039
Severity
CRITICAL
CVSS
9.1
EPSS
0.55%
Original NVD Description
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.
Related CVEs
Other vulnerabilities affecting the same vendor(s)