8.8
CVSSv3

CVE-2022-2193

Published: 19/07/2022 Updated: 27/07/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated malicious users to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions before 6.14.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hypr hypr server