« Volver al listado

CVE-2013-4177

Estado: ModificadaMedia (5)—

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4177",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-29T14:19:07.080",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/59884",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1995482",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1995634",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/1995706",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/59884",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1995482",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1995634",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/1995706",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo de inicio de sesión de Google Authenticator 6.x-1.x anterior a 6.x-1.2 y 7.x-1.x anterior a 7.x-1.4 para Drupal no identifica debidamente nombres de cuentas de usuarios, lo que podría permitir a atacantes remotos evadir el requisito de autenticación de dos factores a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:56:45.773",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:6.x-1.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BC6D784-2C77-4664-B09F-712B10A809DF"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:6.x-1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF76FBDC-EF6B-4038-94C1-8FD67B0D8518"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:6.x-1.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38772692-D0CF-4EC9-923B-729D75A5B36E"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:6.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95720EE4-FBB1-40FA-A62A-0B28802ED524"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:6.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C89CDB4-C3D6-4801-9C43-2D4B001435D6"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1593C73-F1B6-4A8B-8DAE-C66FE555563E"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9907AF35-E82F-4B69-AC66-712D0E06B808"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.0:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9E6CBF0-1973-4130-A41F-AE03D1D3E421"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4A022FA-FF85-4878-8CB4-1AB0530ABD12"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AB4FF45-C6BC-476F-A7B0-6D183AA52C0B"
            },
            {
              "criteria": "cpe:2.3:a:google_authenticator_login_project:ga_login:7.x-1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81C4AB32-0216-45C0-91CE-3ADC5B2DB84A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}