Description
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48081 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct. |
References
| Link | Providers |
|---|---|
| https://www.gruppotim.it/it/footer/red-team.html |
|
History
Fri, 07 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-07T16:33:01.070Z
Reserved: 2022-11-11T00:00:00.000Z
Link: CVE-2022-45173
Updated: 2024-08-03T14:09:56.558Z
Status : Modified
Published: 2023-04-14T14:15:10.357
Modified: 2025-02-07T17:15:22.550
Link: CVE-2022-45173
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD