Multi Factor Authentication Bypass in various versions of Abacus ERP
Published Apr 19, 2022
8.8
HIGHCVSS 3.1
EPSS 2.89%
Description
A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of 2022-01-15; v2019 versions later than R5 (service pack); v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15; v2018 versions prior to R7 of 2020-04-15; v2017 version and prior versions and prior versions.
Affected products
-
- Version R5 (service pack)StatusaffectedConstraints<v2018*
- Version R5 (service pack)StatusaffectedConstraints<v2019*
- Version v2020StatusaffectedConstraints<R6 of 2022-01-15
- Version v2021StatusaffectedConstraints<R4 of 2022-01-15
- Version v2022StatusaffectedConstraints<R1 of 2022-01-15
- Version v2017StatusunaffectedConstraints<=and prior versions
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Abacus Research AG | Abacus ERP | n/a |
|
- ≥ r7
- ≥ r5
- < r6
- < r4
- < r1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Install the available hot fixes and / or service packs from 2022-01-15 or newer
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.89% (0.02885) | 86.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.76% (0.02760) | 84.30th | v5 (v2026.06.15) |
| Apr 28, 2025 | 1.63% (0.01634) | 80.86th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.24% (0.00244) | 45.69th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.33% (0.00326) | 71.69th | v3 (v2023.03.01) |
| Jul 11, 2024 | 0.33% (0.00326) | 71.06th | v3 (v2023.03.01) |
| Apr 3, 2024 | 0.29% (0.00287) | 68.30th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.27% (0.00266) | 66.69th | v3 (v2023.03.01) |
| Nov 25, 2023 | 0.27% (0.00266) | 64.08th | v3 (v2023.03.01) |
| Nov 10, 2023 | 0.25% (0.00250) | 62.72th | v3 (v2023.03.01) |
| Apr 26, 2023 | 0.21% (0.00205) | 56.97th | v3 (v2023.03.01) |
| Mar 20, 2023 | 0.13% (0.00131) | 46.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00117) | 43.93th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Oct 15, 2022 | 1.05% (0.01055) | 50.69th | v2 (v2022.01.01) |
| Apr 19, 2022 | 1.05% (0.01055) | 48.68th | v2 (v2022.01.01) |
References (1)
- https://www.redguard.ch/advisories/abacus_mfa_bypass.txt x_refsource_CONFIRMExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.redguard.ch/advisories/abacus_mfa_bypass.txt | x_refsource_CONFIRMExploitThird Party Advisory |
Change history (0)
No recorded changes yet.