CVE-2024-37343

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default configuration could click on it while the attacker has a valid tunnel session with the server. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:23

Type Values Removed Values Added
References () https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37343/ - Vendor Advisory () https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37343/ - Vendor Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 4.8

06 Aug 2024, 13:48

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross Site Scripting en la consola administrativa de Secure Access de Absolute Secure Access anterior a la versión 13.06. Los atacantes con credenciales de túnel válidas pueden pasar un script de longitud limitada a la consola administrativa que luego se almacena temporalmente donde un administrador que utilice una configuración no predeterminada podría hacer clic en él mientras el atacante tiene una sesión de túnel válida con el servidor. El alcance no cambia, no hay pérdida de confidencialidad. El impacto en la disponibilidad del sistema es nulo, el impacto en la integridad del sistema es alto.
References () https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37343/ - () https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1306/cve-2024-37343/ - Vendor Advisory
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
First Time Absolute
Absolute secure Access
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 5.4

20 Jun 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 17:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37343

Mitre link : CVE-2024-37343

CVE.ORG link : CVE-2024-37343


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')