Back to overview

CVE-2024-27928

MEDIUM
5.9
CVSS 4.0
Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can 1) reset the password via email and then 2) reset the 2FA token via email. This way they reduce 2FA to 1FA (email access). Note that most email providers require 2FA to access email, so this issue is not very likely to cause issues. Version 5.0.0 fixes the issue. No known workarounds are available.

Metadata

CVE ID
CVE-2024-27928
State
PUBLISHED
Assigner
GitHub_M
Reserved
2024-02-28 15:14 UTC
Published
2026-06-17 22:12 UTC
Last updated
2026-06-17 22:12 UTC
Primary CWE
CWE-308
CWE-308: Use of Single-factor Authentication
Vendor / Product
vantage6 / vantage6
Sources
cve.org  ·  NVD

Severity & Metrics

5.9 MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
vantage6 vantage6 < 5.0.0
Weakness (CWE)
CWESourceDescription
CWE-308 cna CWE-308: Use of Single-factor Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
References (3)
Back to overview