Fido2 is vulnerable to Authentication Bypass by Capture-replay
37
Low Risk
Fido2's assertion verifier accepts an authenticator assertion whose signCount is 0 even when the stored signature counter for the credential is non-zero. The clone detection check only runs when the reported signCount is greater than zero, so a cloned or replaying authenticator that reports a zero counter skips the WebAuthn clone detection branch. This lets a captured or duplicated credential keep authenticating without the server flagging it as a possible clone. The fix enters the clone detection branch whenever the stored counter is non-zero, regardless of the reported counter value.
You are affected if you are using a version that falls within the vulnerable range.
Fido2 is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.1 - 4.0.1.
Upgrade the Fido2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.