CVE-2022-23849: Medium severity devolutions password hub vulnerability
The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23849?
CVE-2022-23849 is a vulnerability in the biometric lock in Devolutions Password Hub for iOS before 2021.3.4 that allows attackers to access the application due to authentication bypass.
How can an attacker exploit CVE-2022-23849?
An attacker can exploit CVE-2022-23849 by rapidly making failed biometric authentication attempts to bypass the biometric lock in Devolutions Password Hub for iOS.
What is the severity of CVE-2022-23849?
CVE-2022-23849 has a severity value of 6.6, which is considered medium severity.
Which version of Devolutions Password Hub for iOS is affected by CVE-2022-23849?
Devolutions Password Hub for iOS before version 2021.3.4 is affected by CVE-2022-23849.
How do I fix CVE-2022-23849?
To fix CVE-2022-23849, it is recommended to update Devolutions Password Hub for iOS to version 2021.3.4 or later.