CVE-2015-7225 affects Tinfoil Devise-two-factor versions prior to 2.0.0, stemming from an improper implementation of RFC 6238 where successfully validated one-time passwords (OTPs) are not invalidated. This medium-severity vulnerability (CVSS 5.3) allows authenticated attackers to reuse an OTP within the same time-step, potentially gaining unauthorized access to a user's account. Exploitation requires a man-in-the-middle attack or shoulder surfing to obtain the OTP, making the attack complexity high. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0CPE matchmatch criteria | cpe:2.3:a:tinfoilsecurity:devise-two-factor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.