5.5
CVE-2024-45673
- EPSS 0.02%
- Published 21.02.2025 17:15:12
- Last modified 27.08.2025 22:15:44
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Security Verify Bridge Directory Sync Version >= 1.0.1 <= 1.0.12
Ibm ≫ Security Verify Gateway For Radius Version >= 1.0.1 <= 1.0.11
Ibm ≫ Security Verify Gateway For Windows Login Version >= 1.0.1 <= 1.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.029 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
psirt@us.ibm.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-260 Password in Configuration File
The product stores a password in a configuration file that might be accessible to actors who do not know the password.