A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17417 | A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services. |
Fixes
Solution
Tenable has released Tenable Identity Exposure Secure Relay Version 3.59.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure https://www.tenable.com/downloads/identity-exposure
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2024-03 |
|
History
Tue, 17 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable identity Exposure |
|
| CPEs | cpe:2.3:a:tenable:identity_exposure:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tenable
Tenable identity Exposure |
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T18:48:21.833Z
Reserved: 2024-02-20T19:24:25.274Z
Link: CVE-2024-1683
Updated: 2024-08-01T18:48:21.833Z
Status : Analyzed
Published: 2024-02-23T01:15:52.700
Modified: 2024-12-17T17:10:15.347
Link: CVE-2024-1683
No data.
OpenCVE Enrichment
No data.
EUVD