Vulnerability Description
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Delinea | Secret Server | 11.4.000000 |
Related Weaknesses (CWE)
References
- https://docs.delinea.com/online-help/secret-server/admin/unlimited-administratioBroken Link
- https://docs.delinea.com/online-help/secret-server/release-notes/ssc-rn-2024-02-Release Notes
- https://trust.delinea.com/Vendor Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25652Third Party Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25652Third Party Advisory
FAQ
What is CVE-2024-25652?
CVE-2024-25652 is a vulnerability with a CVSS score of 7.6 (HIGH). In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report fun...
How severe is CVE-2024-25652?
CVE-2024-25652 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-25652?
Check the references section above for vendor advisories and patch information. Affected products include: Delinea Secret Server.