PT-2024-16338 · Unknown+1 · Boundary Enterprise+1

Published

2024-02-05

·

Updated

2024-06-28

·

CVE-2024-1052

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Boundary and Boundary Enterprise (affected versions not specified)
Description The issue allows session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1052
GHSA-VH73-Q3RW-QX7W
GO-2024-2532

Affected Products

Boundary
Boundary Enterprise