A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-17417 A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
Fixes

Solution

Tenable has released Tenable Identity Exposure Secure Relay Version 3.59.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure https://www.tenable.com/downloads/identity-exposure


Workaround

No workaround given by the vendor.

History

Tue, 17 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenable
Tenable identity Exposure
CPEs cpe:2.3:a:tenable:identity_exposure:*:*:*:*:*:*:*:*
Vendors & Products Tenable
Tenable identity Exposure

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-01T18:48:21.833Z

Reserved: 2024-02-20T19:24:25.274Z

Link: CVE-2024-1683

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.833Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-23T01:15:52.700

Modified: 2024-12-17T17:10:15.347

Link: CVE-2024-1683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.