PT-2024-32288 · Mfasoft · Mfasoft Secure Authentication Server
Published
2024-09-16
·
Updated
2024-10-24
·
CVE-2024-46937
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
MFASOFT Secure Authentication Server (SAS) versions 1.8.x through 1.9.x before 1.9.040924
Description
An improper access control vulnerability in the "/api-selfportal/get-info-token-properties" endpoint allows remote attackers to gain access to user tokens without authentication. This can be achieved through a brute-force attack on the
serial parameter by number identifier.Recommendations
For MFASOFT Secure Authentication Server (SAS) versions 1.8.x through 1.9.x before 1.9.040924, consider disabling access to the "/api-selfportal/get-info-token-properties" endpoint until a patch is available. As a temporary workaround, restrict the use of the
serial parameter to minimize the risk of exploitation. Update to version 1.9.040924 or later to resolve the issue.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mfasoft Secure Authentication Server