CVE-2023-4589
Insufficient verification of data authenticity vulnerability in Delinea Secret Server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process lacks digital signatures and fails to validate the integrity of the update package, allowing the attacker to inject malicious applications during the update.
Vulnerabilidad de verificación insuficiente de autenticidad de datos en Delinea Secret Server, en su versión v10.9.000002. Un atacante con una cuenta de administrador podría realizar actualizaciones de software sin los mecanismos adecuados de verificación de integridad. En este escenario, el proceso de actualización carece de firmas digitales y no logra validar la integridad del paquete de actualización, lo que permite al atacante inyectar aplicaciones maliciosas durante la actualización.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-08-29 CVE Reserved
- 2023-09-06 CVE Published
- 2024-09-12 EPSS Updated
- 2024-09-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-delinea-secret-server | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Delinea Search vendor "Delinea" | Secret Server Search vendor "Delinea" for product "Secret Server" | 10.9.000002 Search vendor "Delinea" for product "Secret Server" and version "10.9.000002" | - |
Affected
|