CVE-2024-51720

MEDIUM

SecuSUITE <5.0.420 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.

Scores

CVSS v3 4.8
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307 CWE-334
Status published
Products (1)
BlackBerry/SecuSUITE 5.0.420
Published Nov 12, 2024
Tracked Since Feb 18, 2026