PT-2025-35801 · Quest · Quest One Identity

Vigneshrajan54_88115

·

Published

2025-09-03

·

Updated

2025-09-04

·

CVE-2025-56689

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Quest One Identity version 7.5.1.20903
Description A crafted response manipulation can bypass the One-Time Password (OTP) on the Multi-Factor Authentication (MFA) page, leading to unauthorized access to the Privileged Access Management (PAM) portal without OTP verification. This allows attackers to control arbitrary accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-56689

Affected Products

Quest One Identity