CVE-2024-25652

HIGH

Delinea Secret Server 11.4 - Unauthorized Access to Remote Sessions via Custom Legacy Report

Title source: llm
STIX 2.1

Description

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

Scores

CVSS v3 7.6
EPSS 0.0059
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
delinea/secret_server 11.4.000000
Published Mar 14, 2024
Tracked Since Feb 18, 2026