THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-5812

Smart Rule Overwrite Bypass in BeyondInsight PasswordSafe

Reserved:2024-06-10
Published:2024-06-11
Updated:2024-06-11

Description

A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.



LOW: 3.3CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-290 Authentication Bypass by Spoofing

Product status

Default status
unaffected

24.1.0 before 24.1.1
affected

23.3.0 before 23.3.0.959
affected

23.2.0 before 23.2.0.1293
affected

References

https://www.beyondtrust.com/trust-center/security-advisories/bt24-07

cve.org CVE-2024-5812

nvd.nist.gov CVE-2024-5812

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-5812