Skip to content

SECURE Access push nofitications after reset data

Low
Abraxas-Bot published GHSA-r94x-3qf7-frv5 Feb 16, 2024

Package

Abraxas SECURE Access App (iOS / Android)

Affected versions

< 2.8.0

Patched versions

2.8.0

Description

Short Description

Incomplete unregistration of 2FA push notification service after reset

Reporting Date

  1. August 2023

Details

When using the RESET ALL DATA function in the 2FA authenticator app, the push notification service (e.g. APN on iOS) was not properly unsubscribed. This resulted in encrypted push notifications continuing to be sent to the previously unregistered device during new user logins (as long as no new 2fa device has been registered).

Impact

Low

References

  • Bug Bounty ID: MAYOR-huarache (Public)
  • Internal ID: Request-ID 2203

❤ Thanks to

Hassan Jawaid for reporting the described issue.

Severity

Low
1.7
/ 10

CVSS base metrics

Attack vector
Physical
Attack complexity
High
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

CVE ID

No known CVE

Weaknesses