CVE-2024-51720

MEDIUM

SecuSUITE <5.0.420 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0031
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307 CWE-334
Status published
Products (1)
BlackBerry/SecuSUITE 5.0.420
Published Nov 12, 2024
Tracked Since Feb 18, 2026