CVE-2024-45673

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7183801 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 Jun 2025, 23:36

Type Values Removed Values Added
Summary
  • (es) IBM Security Verify Bridge Directory Sync 1.0.1 a 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 a 1.0.10 e IBM Security Verify Gateway for Radius 1.0.1 a 1.0.11 almacenan las credenciales de usuario en archivos de configuración que pueden ser leídos por un usuario local.
First Time Ibm security Verify Gateway For Windows Login
Ibm security Verify Gateway For Radius
Microsoft
Linux
Ibm
Microsoft windows
Ibm security Verify Bridge Directory Sync
Linux linux Kernel
References () https://www.ibm.com/support/pages/node/7183801 - () https://www.ibm.com/support/pages/node/7183801 - Vendor Advisory
CPE cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*

21 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 17:15

Updated : 2025-06-18 23:36


NVD link : CVE-2024-45673

Mitre link : CVE-2024-45673

CVE.ORG link : CVE-2024-45673


JSON object : View

Products Affected

ibm

  • security_verify_bridge_directory_sync
  • security_verify_gateway_for_windows_login
  • security_verify_gateway_for_radius

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-260

Password in Configuration File