CVE-2024-9513

LOW

Netadmin IAM < 3.5 - Information Exposure via Username Argument Discrepancy

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-9513. PoCs published by ELIZEUOPAIN.

AI-analyzed exploit summary This exploit demonstrates user enumeration in Active Directory via NetAdmin IAM by sending HTTP POST requests to a vulnerable endpoint and checking response status codes. It iterates through a list of usernames to identify valid accounts.

Description

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to information exposure through discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure is planning to release a fix in mid-October 2024.

Exploits (1)

nomisec WORKING POC 1 stars
by ELIZEUOPAIN · poc
https://github.com/ELIZEUOPAIN/Exploit-CVE-2024-9513-NetAdmin-IAM-Allows-User-Enumeration-In-Active-Directory

This exploit demonstrates user enumeration in Active Directory via NetAdmin IAM by sending HTTP POST requests to a vulnerable endpoint and checking response status codes. It iterates through a list of usernames to identify valid accounts.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: NetAdmin IAM 3.5
No auth needed
Prerequisites: A list of usernames to test · Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.279212
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.279212
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.413498

Scores

CVSS v3 3.7
EPSS 0.0163
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (1)
netadmin/netadmin_iam < 3.5
Published Oct 04, 2024
Tracked Since Feb 18, 2026