PT-2024-32288 · Mfasoft · Mfasoft Secure Authentication Server

Published

2024-09-16

·

Updated

2024-10-24

·

CVE-2024-46937

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions MFASOFT Secure Authentication Server (SAS) versions 1.8.x through 1.9.x before 1.9.040924
Description An improper access control vulnerability in the "/api-selfportal/get-info-token-properties" endpoint allows remote attackers to gain access to user tokens without authentication. This can be achieved through a brute-force attack on the serial parameter by number identifier.
Recommendations For MFASOFT Secure Authentication Server (SAS) versions 1.8.x through 1.9.x before 1.9.040924, consider disabling access to the "/api-selfportal/get-info-token-properties" endpoint until a patch is available. As a temporary workaround, restrict the use of the serial parameter to minimize the risk of exploitation. Update to version 1.9.040924 or later to resolve the issue.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01945
CVE-2024-46937

Affected Products

Mfasoft Secure Authentication Server