Multi-Factor Authentication Bypass in NetIQ Advanced Authentication
CVE-2022-38753

6.3MEDIUM

Key Information:

Vendor

Microfocus

Vendor
CVE Published:
28 November 2022

What is CVE-2022-38753?

A vulnerability has been identified in NetIQ Advanced Authentication, allowing attackers to bypass multi-factor authentication measures. This flaw can lead to unauthorized access, as it undermines the essential security layer intended to protect user accounts. Users of affected versions should apply the latest security updates to mitigate potential risks associated with this vulnerability.

Affected Version(s)

NetIQ Advanced Authentication NetIQ Advanced Authentication versions prior to 6.4 SP1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.