← back
CVE-2024-4555

User impersonation with MFA when configure in specific way

CVSS 7.7 HIGHEPSS 0.3%CWE-266
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →