CVE Vulnerabilities

CVE-2025-43798

Missing Critical Step in Authentication

Published: Sep 15, 2025 | Modified: Dec 16, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.

Weakness

The product implements an authentication technique, but it skips a step that weakens the technique.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay2023.q3.1 (including)2023.q3.5 (excluding)
Digital_experience_platformLiferay7.3 (including)7.3 (including)
Digital_experience_platformLiferay7.3-fix_pack_1 (including)7.3-fix_pack_1 (including)
Digital_experience_platformLiferay7.3-fix_pack_2 (including)7.3-fix_pack_2 (including)
Digital_experience_platformLiferay7.3-service_pack_1 (including)7.3-service_pack_1 (including)
Digital_experience_platformLiferay7.3-service_pack_2 (including)7.3-service_pack_2 (including)
Digital_experience_platformLiferay7.3-service_pack_3 (including)7.3-service_pack_3 (including)
Digital_experience_platformLiferay7.3-update1 (including)7.3-update1 (including)
Digital_experience_platformLiferay7.3-update10 (including)7.3-update10 (including)
Digital_experience_platformLiferay7.3-update11 (including)7.3-update11 (including)
Digital_experience_platformLiferay7.3-update12 (including)7.3-update12 (including)
Digital_experience_platformLiferay7.3-update13 (including)7.3-update13 (including)
Digital_experience_platformLiferay7.3-update14 (including)7.3-update14 (including)
Digital_experience_platformLiferay7.3-update15 (including)7.3-update15 (including)
Digital_experience_platformLiferay7.3-update16 (including)7.3-update16 (including)
Digital_experience_platformLiferay7.3-update17 (including)7.3-update17 (including)
Digital_experience_platformLiferay7.3-update18 (including)7.3-update18 (including)
Digital_experience_platformLiferay7.3-update19 (including)7.3-update19 (including)
Digital_experience_platformLiferay7.3-update2 (including)7.3-update2 (including)
Digital_experience_platformLiferay7.3-update20 (including)7.3-update20 (including)
Digital_experience_platformLiferay7.3-update21 (including)7.3-update21 (including)
Digital_experience_platformLiferay7.3-update22 (including)7.3-update22 (including)
Digital_experience_platformLiferay7.3-update23 (including)7.3-update23 (including)
Digital_experience_platformLiferay7.3-update24 (including)7.3-update24 (including)
Digital_experience_platformLiferay7.3-update25 (including)7.3-update25 (including)
Digital_experience_platformLiferay7.3-update26 (including)7.3-update26 (including)
Digital_experience_platformLiferay7.3-update27 (including)7.3-update27 (including)
Digital_experience_platformLiferay7.3-update28 (including)7.3-update28 (including)
Digital_experience_platformLiferay7.3-update29 (including)7.3-update29 (including)
Digital_experience_platformLiferay7.3-update3 (including)7.3-update3 (including)
Digital_experience_platformLiferay7.3-update30 (including)7.3-update30 (including)
Digital_experience_platformLiferay7.3-update31 (including)7.3-update31 (including)
Digital_experience_platformLiferay7.3-update32 (including)7.3-update32 (including)
Digital_experience_platformLiferay7.3-update33 (including)7.3-update33 (including)
Digital_experience_platformLiferay7.3-update34 (including)7.3-update34 (including)
Digital_experience_platformLiferay7.3-update35 (including)7.3-update35 (including)
Digital_experience_platformLiferay7.3-update4 (including)7.3-update4 (including)
Digital_experience_platformLiferay7.3-update5 (including)7.3-update5 (including)
Digital_experience_platformLiferay7.3-update6 (including)7.3-update6 (including)
Digital_experience_platformLiferay7.3-update7 (including)7.3-update7 (including)
Digital_experience_platformLiferay7.3-update8 (including)7.3-update8 (including)
Digital_experience_platformLiferay7.3-update9 (including)7.3-update9 (including)
Digital_experience_platformLiferay7.4 (including)7.4 (including)
Digital_experience_platformLiferay2023.q4.0 (including)2023.q4.0 (including)

References