CVE-2024-45488
SafeGuard for Privileged Passwords < 7.5.2 - Authentication Bypass
Record summary
CVE-2024-45488 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 30, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
privileged_passwordsBrowse safeguard / privileged_passwordsDefault status: unknown | CVE List | Before 7.5.2 | affected |
| Before 7.4.2 | affected | ||
| Before 7.0.5.1LTS | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSafeGuard for Privileged Passwords < 7.5.2 - Authentication BypassCVSS 9.8
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.
Impact
Unauthenticated attackers can bypass authentication and gain unauthorized administrative access to SafeGuard for Privileged Passwords systems.
Remediation
Update One Identity Safeguard for Privileged Passwords to version 7.0.5.1 LTS, 7.4.2, or 7.5.2 or later.
Source: ProjectDiscovery