CVE-2013-7292: Vasco Identikey Authentication Server

Low severity, CVSS 3.5. EPSS: 1.2% chance of exploitation in the next 30 days.

VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.

Affected products

  • Vasco Identikey Authentication Server: version 3.4 only

Published 2014-01-13. Last modified 2026-06-17.