PT-2023-29749 · Delinea · Delinea Pam Secret Server
3V4Si0N
+1
·
Publicado
2023-09-06
·
Atualizado
2023-09-11
·
CVE-2023-4589
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delinea Secret Server version 10.9.000002
Description
The issue is related to insufficient verification of data authenticity in the software update process. An attacker with an administrator account could exploit this by performing software updates without proper integrity verification mechanisms, allowing them to inject malicious applications during the update. The update process lacks digital signatures and fails to validate the integrity of the update package.
Recommendations
For Delinea Secret Server version 10.9.000002, consider disabling the software update feature until a patch is available to prevent potential exploitation. Restrict access to the update mechanism to minimize the risk of malicious application injection. Avoid using the update process until the issue is resolved with proper integrity verification mechanisms in place. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Delinea Pam Secret Server