CVE-2024-37393

HIGH EXPLOITED NUCLEI

Securenvoy Multi-factor Authenticatio... - Cleartext Transmission

Title source: rule

Description

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

Exploits (1)

nomisec SCANNER 1 stars
by noways-io · poc
https://github.com/noways-io/securenvoy-cve-2024-37393

Nuclei Templates (1)

SecurEnvoy Two Factor Authentication - LDAP Injection
CRITICALVERIFIEDby s4e-io
Shodan: title:"SecurEnvoy"
FOFA: title="SecurEnvoy"

Scores

CVSS v3 7.5
EPSS 0.8466
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-11-12
CWE
CWE-319 CWE-89
Status published
Products (1)
securenvoy/multi-factor_authentication_solutions < 9.4.514
Published Jun 10, 2024
Tracked Since Feb 18, 2026