CVE-2022-45173

Name
CVE-2022-45173
Description
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.gruppotim.it/it/footer/red-team.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:* vdesk >= None <= 018

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vdesk edge-community 1.2-r1 ScrumpyJack <scrumpyjack@st.ilet.to> possibly vulnerable
vdesk 3.17-community 1.2-r1 ScrumpyJack <scrumpyjack@st.ilet.to> possibly vulnerable
vdesk 3.18-community 1.2-r1 ScrumpyJack <scrumpyjack@st.ilet.to> possibly vulnerable