Lucene search

K
nvd[email protected]NVD:CVE-2023-4589
HistorySep 06, 2023 - 12:15 p.m.

CVE-2023-4589

2023-09-0612:15:07
CWE-345
web.nvd.nist.gov
vulnerability
delinea secret server
administrator account
software updates
integrity verification
digital signatures
update package
malicious applications

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

38.7%

Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process lacks digital signatures and fails to validate the integrity of the update package, allowing the attacker to inject malicious applications during the update.

Affected configurations

Nvd
Node
delineasecret_serverMatch10.9.000002
VendorProductVersionCPE
delineasecret_server10.9.000002cpe:2.3:a:delinea:secret_server:10.9.000002:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

38.7%

Related for NVD:CVE-2023-4589