Record summary

CVE-2024-45488 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 30, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 7.5.2affected
Before 7.4.2affected
Before 7.0.5.1LTSaffected

Nuclei templates

1
ProjectDiscoveryCRITICALSafeGuard for Privileged Passwords < 7.5.2 - Authentication BypassCVSS 9.8

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

Impact

Unauthenticated attackers can bypass authentication and gain unauthorized administrative access to SafeGuard for Privileged Passwords systems.

Remediation

Update One Identity Safeguard for Privileged Passwords to version 7.0.5.1 LTS, 7.4.2, or 7.5.2 or later.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024auth-bypasssafeguardvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"Safeguard for Privileged Passwords"

Source: ProjectDiscovery

References

3