A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a single-factor authentication scheme gets compromised.
The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cipace | Cipplanner | * | 9.17 (excluding) |