CVE-2024-4303

HIGH

ArmorX APP < 1.5.2 - Improper Authentication via MFA Bypass

Title source: llm
STIX 2.1

Description

ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.

References (1)

Core 1
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7781-ef309-1.html

Scores

CVSS v3 8.8
EPSS 0.0071
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
ArmorX/ArmorX APP earlier - 1.5.2
Published Apr 29, 2024
Tracked Since Feb 18, 2026