CVE-2023-40260

CRITICAL

EmpowerID < 7.205.0.1 - Multi-Factor Authentication Bypass via Email Change

Title source: llm
STIX 2.1

Description

EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes to the new email address (which may be attacker-controlled). NOTE: this is different from CVE-2023-4177, which claims to be about "some unknown processing of the component Multi-Factor Authentication Code Handler" and thus cannot be correlated with other vulnerability information.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
https://seclists.org/fulldisclosure/2023/Aug/3

Scores

CVSS v3 9.1
EPSS 0.0053
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
empowerid/empowerid < 7.205.0.1
Published Aug 11, 2023
Tracked Since Feb 18, 2026