← back
CVE-2024-33891

CVE-2024-33891

CVSS 8.8 HIGHEPSS 1.0%CWE-321
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:U/UI:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →