PT-2024-18988 · Microsoft · Azure Ipam

Dcmattyg

·

Published

2024-01-10

·

Updated

2024-01-19

·

CVE-2024-21638

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Azure IPAM versions prior to 3.0.0
Description The issue concerns the lack of validation of the passed-in authentication token in Azure IPAM, which may allow an attacker to impersonate any privileged user and access data stored within the IPAM instance and subsequently from Azure, resulting in an elevation of privilege.
Recommendations For versions prior to 3.0.0, update to version 3.0.0 to resolve the issue.

Exploit

Fix

Improper Privilege Management

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-21638
GHSA-M8MP-JQ4C-G8J6

Affected Products

Azure Ipam