CVE-2024-45394
NixOS vulnerability analysis and mitigation

Overview

Authenticator, a browser extension for generating two-step verification codes, was found to have a significant security vulnerability in versions 7.0.0 and below. The vulnerability (CVE-2024-45394) involves encryption keys for user data being stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF, making them susceptible to brute-force attacks. The vulnerability was discovered through a code review sponsored by the University of Luxembourg and was publicly disclosed on September 3, 2024 (GitHub Advisory).

Technical details

The vulnerability stems from inadequate encryption strength (CWE-326) and the use of weak encoding for passwords (CWE-261). The issue received a CVSS v3.1 base score of 8.8 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating local access requirements but high potential impact on confidentiality, integrity, and availability (NVD).

Impact

Attackers who obtain a copy of a user's data can potentially brute-force the user's encryption key, potentially compromising the security of two-factor authentication codes. This could lead to unauthorized access to accounts protected by the compromised two-factor authentication (GitHub Advisory).

Mitigation and workarounds

Users are advised to upgrade to version 8.0.0 or above, which automatically migrates away from the weak encoding on first login. Additionally, users should destroy any encrypted backups made with versions prior to 8.0.0 to prevent potential exploitation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-65622MEDIUM5.4
  • PHPPHP
  • snipe/snipe-it
NoYesDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management