Horizon Alert
Summary of the vulnerability and why it matters
An unauthenticated vulnerability in a password reset function of EMSigner software could allow unauthorized access to all user accounts, including those with administrator privileges. This issue stems from incorrect access control that can be exploited via a crafted password reset token.
- Unauthenticated users can access all accounts.
- Protects sensitive data and administrative functions.
- Confirm if EMSigner 2.8.7 is in use.
Attack Path
How an attacker could exploit the issue
An attacker can target the password reset feature of EMSigner to gain unauthorized access to user accounts. This can be achieved by manipulating the password reset token, potentially allowing the attacker to impersonate any user, including administrators.
- No authentication required.
- Exploits password reset token.
- Leads to full account compromise.
Live Threat
Current exploitation, exposure, and threat context
Incorrect access control in the password reset function of EMSigner, when accessible online, could allow unauthenticated attackers to gain access to any user account, including administrator accounts, by manipulating password reset tokens.
- All registered user accounts, including administrators.
- Via crafted password reset tokens.
- Unauthorized account access.
Operational Fix
Recommended remediation, mitigation, and detection steps
The critical vulnerability in EMSigner's password reset function requires immediate attention from teams managing the application and its infrastructure. The first practical step is to identify all instances of EMSigner, confirm their internet accessibility and business criticality, and then assign ownership for remediation planning.
- Application owners must drive remediation.
- Verify internet exposure and business impact.
- Plan immediate mitigation or patching.