Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22080 | Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection. |
| Link | Providers |
|---|---|
| https://www.cirosec.de/sa/sa-2025-006 |
|
Mon, 21 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection. | |
| Title | Insecure authentication due to missing bruteforce protection and runtime manipulation in Two App Studio Journey 5.5.6 for iOS | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cirosec
Published:
Updated: 2025-08-27T06:34:27.134Z
Reserved: 2025-04-16T10:48:40.810Z
Link: CVE-2025-41459
Updated: 2025-07-21T12:25:04.341Z
Status : Deferred
Published: 2025-07-21T11:15:23.810
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41459
No data.
OpenCVE Enrichment
No data.
EUVD