CVE-2024-37393

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:securenvoy:multi-factor_authentication_solutions:*:*:*:*:*:*:*:*

History

03 Jul 2024, 02:04

Type Values Removed Values Added
CWE CWE-89

12 Jun 2024, 17:56

Type Values Removed Values Added
References () https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/ad2ce8fa-42a0-4371-ad18-5d1d1c488b22 - () https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-ada2/ad2ce8fa-42a0-4371-ad18-5d1d1c488b22 - Exploit
References () https://securenvoy.com/support/ - () https://securenvoy.com/support/ - Product
References () https://www.optistream.io/blogs/tech/securenvoy-cve-2024-37393 - () https://www.optistream.io/blogs/tech/securenvoy-cve-2024-37393 - Exploit, Third Party Advisory
Summary
  • (es) Existen múltiples vulnerabilidades de inyecciones LDAP en SecurEnvoy MFA antes de la versión 9.4.514 debido a una validación incorrecta de la entrada proporcionada por el usuario. Un atacante remoto no autenticado podría exfiltrar datos de Active Directory mediante ataques de inyección LDAP ciegos contra el servicio DESKTOP expuesto en el endpoint HTTP /secserver. Esto puede incluir ms-Mcs-AdmPwd, que tiene una contraseña de texto plano para la función Solución de contraseña de administrador local (LAPS).
CPE cpe:2.3:a:securenvoy:multi-factor_authentication_solutions:*:*:*:*:*:*:*:*
First Time Securenvoy
Securenvoy multi-factor Authentication Solutions
CWE CWE-319
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

10 Jun 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 20:15

Updated : 2024-07-03 02:04


NVD link : CVE-2024-37393

Mitre link : CVE-2024-37393

CVE.ORG link : CVE-2024-37393


JSON object : View

Products Affected

securenvoy

  • multi-factor_authentication_solutions
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')