CVE-2024-12839 - CVE House
Back to Database
Status published High CVE-2024-12839

Changing Information Technology CGFIDO - Authentication Bypass

Vulnerability Description

The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12839

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Changing Information Technology

View all reports →

Affected Software

CGFIDO
Vulnerable Versions:
0

Timeline

Official Publish: December 31st, 2024
Last Modified: December 31st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.