Information disclosure in Versa Director - CVE-2024-45229

 

Information disclosure in Versa Director - CVE-2024-45229

Published: September 23, 2024


Vulnerability identifier: #VU97638
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45229
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the REST API exposes authentication tokens of other currently logged-in users in an error message. A remote non-authenticated attacker can send a specially crafted HTTP request, obtain an authentication token and use it to invoke additional APIs on port 9183.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Versa Director

How to mitigate CVE-2024-45229

Install updates from vendor's website.

Versa Director - addressed in versions 21.2.3 HF, 22.1.2 HF, 22.1.3 HF, 22.1.4 HF

External References

Related Security Bulletins