SB2024092319 - Information disclosure in Versa Director



SB2024092319 - Information disclosure in Versa Director

Published: September 23, 2024

Security Bulletin ID SB2024092319
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2024-45229)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the REST API exposes authentication tokens of other currently logged-in users in an error message. A remote non-authenticated attacker can send a specially crafted HTTP request, obtain an authentication token and use it to invoke additional APIs on port 9183.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install update from vendor's website.