CVE-2021-42791: High severity veridiumid vulnerability
An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any other user. The text contained in the push notification can also be modified. If a user who receives the notification accepts it, then the user who triggered the notification can obtain the accepting user's login certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42791?
CVE-2021-42791 is classified as a high severity vulnerability due to the potential for unauthorized push notification access.
How do I fix CVE-2021-42791?
To fix CVE-2021-42791, ensure that proper access control measures are implemented to restrict push notification requests to authorized users.
What impact does CVE-2021-42791 have on user security?
CVE-2021-42791 allows an attacker to send unauthorized push notifications to any user, compromising user privacy and potentially spreading misinformation.
Is CVE-2021-42791 specific to any version of VeridiumAD?
Yes, CVE-2021-42791 specifically affects VeridiumAD version 2.5.3.0.
Can CVE-2021-42791 be exploited remotely?
Yes, CVE-2021-42791 can be exploited remotely as it involves HTTP requests that do not require authentication for triggering notifications.