Impact
SEP sesam before 5.2.0.24 mishandles system treats usernames case-sensitive while Active Directory is case-insensitive, allowing an attacker to create multiple SEP sesam accounts that map to the same AD account, and register an additional One Time Password authenticator for that account, thereby weakening the MFA protection. The underlying weakness is identified as CWE-180, which describes improper handling of value comparison and normalization.
Affected Systems
All SEP sesam deployments using version <5.2.0.24 with Active Directory authentication and enforce MFA. The flaw is specific to environments where usernames are compared without normalizing the case, causing duplicate symbolic accounts for a single AD account.
Risk and Exploitability
The CVSS score of 3.5 indicates moderate severity. The EPSS score is below 1%, indicating very low current exploitation probability. The vulnerability is not listed in CISA KEV catalog, suggesting no publicly known exploit. The risk remains moderate primarily in environments where MFA is the main defense, as the flaw allows reduction of MFA effectiveness.
OpenCVE Enrichment