PT-2024-33691 · Ibm · Ibm Security Verify Access Appliance

Antonin B

+2

·

Published

2024-11-29

·

Updated

2024-12-03

·

CVE-2024-49806

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8
Description: The issue concerns hard-coded credentials, such as a password or cryptographic key, used by the appliance for its own inbound authentication, outbound communication to external components, or encryption of internal data. This poses serious cybersecurity risks.
Recommendations: For versions 10.0.0 through 10.0.8, consider disabling the use of hard-coded credentials as a temporary workaround until a patch is available. Restrict access to the appliance to minimize the risk of exploitation. Avoid using the affected appliance for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-49806

Affected Products

Ibm Security Verify Access Appliance