CVE Vulnerabilities

CVE-2022-1955

Improper Authentication

Published: Jun 30, 2022 | Modified: Jul 11, 2022
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Session 1.13.0 allows an attacker with physical access to the victims device to bypass the applications password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Session Opft 1.13.0 (including) 1.13.0 (including)

Potential Mitigations

References