CVE-2024-1403
CRITICALOpenEdge < 11.7.19 - Authentication Bypass via Credential Handling Failure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-1403. PoCs published by horizon3ai.
AI-analyzed exploit summary This repository contains a functional Java exploit for CVE-2024-1403, an authentication bypass vulnerability in Progress OpenEdge. The PoC leverages RMI to connect to the AdminServer interface using a crafted 'NT AUTHORITY\SYSTEM' credential, demonstrating unauthorized access to system plugins.
Description
In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified. The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.
Exploits (1)
This repository contains a functional Java exploit for CVE-2024-1403, an authentication bypass vulnerability in Progress OpenEdge. The PoC leverages RMI to connect to the AdminServer interface using a crafted 'NT AUTHORITY\SYSTEM' credential, demonstrating unauthorized access to system plugins.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H