CVE-2024-25653

MEDIUM

Delinea Secret Server 11.4 - Broken Access Control in Report Functionality

Title source: llm
STIX 2.1

Description

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25653

Scores

CVSS v3 4.3
EPSS 0.0040
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
delinea/secret_server 11.4.000000
Published Mar 14, 2024
Tracked Since Feb 18, 2026