Security Advisory

CVE-2022-2193

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-07-19 14:07:50
Last updated 2024-08-03 00:32:08
Assigner HYPR
CVSS score 7.5
State PUBLISHED

Description

Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to 6.14.1.