AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-12839

HIGH · CVSS 8.8 EPSS 0.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-12-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.

CVE
CVE-2024-12839
Severity
HIGH
CVSS
8.8
EPSS
0.70%

Original NVD Description

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.