PT-2024-33691 · Ibm · Ibm Security Verify Access Appliance
Antonin B
+2
·
Published
2024-11-29
·
Updated
2024-12-03
·
CVE-2024-49806
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8
Description:
The issue concerns hard-coded credentials, such as a password or cryptographic key, used by the appliance for its own inbound authentication, outbound communication to external components, or encryption of internal data. This poses serious cybersecurity risks.
Recommendations:
For versions 10.0.0 through 10.0.8, consider disabling the use of hard-coded credentials as a temporary workaround until a patch is available. Restrict access to the appliance to minimize the risk of exploitation. Avoid using the affected appliance for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Verify Access Appliance