// For flags

CVE-2024-1403

Authentication Bypass in OpenEdge Authentication Gateway and AdminServer

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The
vulnerability is a bypass to authentication based on a failure to properly
handle username and password. Certain unexpected
content passed into the credentials can lead to unauthorized access without proper
authentication.

En OpenEdge Authentication Gateway y AdminServer anteriores a 11.7.19, 12.2.14, 12.8.1 en todas las plataformas compatibles con el producto OpenEdge, se identificó una vulnerabilidad de omisión de autenticación. La vulnerabilidad es una omisión de la autenticación basada en una falla al manejar adecuadamente el nombre de usuario y la contraseña. Cierto contenido inesperado que se pasa a las credenciales puede provocar un acceso no autorizado sin la autenticación adecuada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-02-09 CVE Reserved
  • 2024-02-27 CVE Published
  • 2024-02-28 EPSS Updated
  • 2024-03-06 First Exploit
  • 2024-08-12 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-305: Authentication Bypass by Primary Weakness
CAPEC
  • CAPEC-115: Authentication Bypass
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress
Search vendor "Progress"
OpenEdge
Search vendor "Progress" for product "OpenEdge"
>= 11.7.0 < 11.7.19
Search vendor "Progress" for product "OpenEdge" and version " >= 11.7.0 < 11.7.19"
en
Affected
Progress
Search vendor "Progress"
OpenEdge
Search vendor "Progress" for product "OpenEdge"
>= 12.2.0 < 12.2.14
Search vendor "Progress" for product "OpenEdge" and version " >= 12.2.0 < 12.2.14"
en
Affected
Progress
Search vendor "Progress"
OpenEdge
Search vendor "Progress" for product "OpenEdge"
>= 12.8.0 < 12.8.1
Search vendor "Progress" for product "OpenEdge" and version " >= 12.8.0 < 12.8.1"
en
Affected