Improper Verification of Cryptographic Signature in elliptic - CVE-2024-42459

 

Improper Verification of Cryptographic Signature in elliptic - CVE-2024-42459

Published: September 19, 2024


Vulnerability identifier: #VU97606
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42459
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error when handling EDDSA signatures. A remote attacker can bypass signature-based security checks.

Affected software

elliptic
Data Product Hub
Storage Scale
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
QRadar Deployment Intelligence App
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
QRadar Log Source Management App
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
Fedora
Splunk Enterprise
yarnpkg
Multicluster Engine for Kubernetes
Splunk Enterprise Security (ES)
IBM API Connect

How to mitigate CVE-2024-42459

Install updates from vendor's website.

elliptic - update to 6.5.7
Data Product Hub - update to 5.0.3
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
Cognos Analytics Mobile (Android) - update to 1.1.21
Cognos Analytics Mobile (iOS) - update to 1.1.21
IBM Cloud Pak for Security - update to 1.11.2.0
yarnpkg - update to 1.22.22-5.el9
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6, 2.5.7, 2.6.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.5, 2.10.6, 2.11.3
QRadar Deployment Intelligence App - update to 3.0.16
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1
IBM Decision Optimization for Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
QRadar Log Source Management App - update to 7.0.11
Splunk Enterprise Security (ES) - update to 8.1.0
IBM API Connect - update to 10.0.9.0

External References

Related Security Bulletins