go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ArmorX Android APP - MFA Bypass

TVN ID TVN-202404014
CVE ID CVE-2024-4303
CVSS 8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products ArmorX Android APP v.1.5.2 and earlier version
Description ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.
Solution Update to v.1.5.3 or later version (release on 20230919)
Credit ChunHao Yang(CHT Security)
Public Date 2024-04-29
Top