PT-2024-27519 · Securenvoy · Securenvoy Mfa

Published

2024-06-10

·

Updated

2025-04-07

·

CVE-2024-37393

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SecurEnvoy MFA versions prior to 9.4.514
Description Multiple LDAP injections vulnerabilities exist due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the "/secserver" HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
Recommendations For versions prior to 9.4.514, update to version 9.4.514 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/secserver" HTTP endpoint to minimize the risk of exploitation. Avoid using the ms-Mcs-AdmPwd attribute in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-37393

Affected Products

Securenvoy Mfa