~ / cve / CVE-2024-XXXXX

CVE-2024-XXXXX

ING Bank — Authentication bypass in a customer-facing portal

Summary

A flaw in the authentication flow of a customer-facing portal allowed an attacker to reach authenticated functionality without valid credentials.

The vulnerability

Explain the root cause here — for example, a trust decision made on a client-controlled value, a missing server-side check, or a broken session-binding step. Describe how the request was crafted and what boundary it crossed.

Impact

With the bypass, an attacker could access account features intended only for authenticated users, which is why this rated critical.

Disclosure

Reported through the vendor’s responsible-disclosure channel and fixed. Replace the external link above with the official advisory.