Impact
The vulnerability in OpenNHP allows an attacker to supply evidence that includes a test_purpose key, causing the system to unconditionally use the FallbackVerifier. As a result, the authentication verification can be bypassed, enabling the attacker to present enrolled measurements and serial numbers from the allowlist and gain unauthorized access. This flaw is a classic authentication bypass.
Affected Systems
The affected software is OpenNHP (the Opennhp project) and all releases up to and including version 1.0.2. Versions newer than 1.0.2 are not affected as the verifier selection logic has been corrected.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA KEV. Attackers likely need to interact with the application’s evidence submission endpoint, so the attack vector is inferred to be remote over the network. The flaw permits bypass of attestation validation, but no execution or privilege escalation beyond unauthorized access is described in the data.
OpenCVE Enrichment