CVE-2021-38299 is an Incorrect Access Control vulnerability affecting Spomky Labs Webauthn Framework versions 3.3.x prior to 3.3.4. An attacker controlling a user's system can bypass user presence checks and log into vulnerable services using an attached FIDO2 authenticator. This vulnerability carries a critical CVSS score of 9.8, indicating a network-based attack with low complexity, leading to high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, Metasploit, Nuclei, or ExploitDB modules, the CVE has garnered significant community discussion and media coverage, including a recent article linking it to potential PassKey account takeovers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.9CPE matchmatch criteria | cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.4CPE matchmatch criteria | cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.