An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by number identifier: GA00001, GA00002, GA00003, etc.

Project Subscriptions

Vendors Products
Mfasoft Subscribe
Secure Authentication Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 20 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Tue, 17 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mfasoft
Mfasoft secure Authentication Server
Weaknesses CWE-284
CPEs cpe:2.3:a:mfasoft:secure_authentication_server:*:*:*:*:*:*:*:*
Vendors & Products Mfasoft
Mfasoft secure Authentication Server
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 13:00:00 +0000

Type Values Removed Values Added
Description An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by number identifier: GA00001, GA00002, GA00003, etc.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-24T16:58:36.442Z

Reserved: 2024-09-15T00:00:00

Link: CVE-2024-46937

cve-icon Vulnrichment

Updated: 2024-09-17T14:08:03.799Z

cve-icon NVD

Status : Modified

Published: 2024-09-16T13:15:10.917

Modified: 2024-10-24T17:35:09.287

Link: CVE-2024-46937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses