HomeTwilioCVE-2020-24655

CVE-2020-24655

MEDIUM
5.1CVSS
Published: 2020-09-10
Updated: 2024-11-21
AI Analysis

Description

A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement).

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
local
Complexity
high
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
none
Availability
none
Weaknesses
CWE-362

Metadata

Primary Vendor
TWILIO
Published
9/10/2020
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

twilio : authy_2-factor_authentication

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief