Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.
History

Tue, 18 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Feb 2025 03:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.
Weaknesses CWE-288
References
Metrics cvssV3_0

{'score': 5.2, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-02-18T15:56:18.426Z

Reserved: 2025-02-14T05:05:05.660Z

Link: CVE-2025-26700

cve-icon Vulnrichment

Updated: 2025-02-18T15:55:54.504Z

cve-icon NVD

Status : Received

Published: 2025-02-17T03:15:09.750

Modified: 2025-02-17T03:15:09.750

Link: CVE-2025-26700

cve-icon Redhat

No data.