Azure IPAM solution Elevation of Privilege Vulnerability
Azure IPAM failed to validate authentication tokens, allowing attackers to impersonate any user and access sensitive IP address data and Azure environment information. This bypasses the intended read-only restrictions and can lead to unauthorized access to critical infrastructure.
The vulnerability stems from insufficient authentication token validation (CWE-269) in Azure IPAM, enabling token forgery or replay attacks where an attacker can impersonate privileged users to extract IP address management data and potentially perform unauthorized Azure resource enumeration. The Service Principal's Reader role at root Management Group level is intended as a mitigation, but lacks effect when authentication controls are bypassed at the application layer.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →