MEDIUM🇬🇧 English

CVE-2025-12810

CVSS 5.3v4.0pub. 2026-01-27upd. 2026-02-06

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation). Problem dotyczy Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. Secret z włączoną funkcją "change password on check in" automatycznie się sprawdza, nawet gdy zmiana hasła nie powiedzie się po osiągnięciu limitu ponownych prób. Pozostawia to secret w niespójnym stanie ze złym hasłem. Naprawienie: Uaktualnij do wersji 11.9.47 lub nowszej. Secret pozostanie checked out gdy zmiana hasła się nie powiedzie.

Pokaż oryginał (EN)

Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit. This leaves the secret in an inconsistent state with the wrong password. Remediation: Upgrade to 11.9.47 or later. The secret will remain checked out when the password change fails.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X
  • Delinea Secret Server

    APP
    Delinea
    11.8.00000111.9.00000611.9.000025
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2023-4589CRITICAL9.1PL ✓ten sam produkt

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8ten sam produkt

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2024-25652HIGH7.6ten sam produkt

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...

CVE-2024-12908MEDIUM6.9ten sam produkt

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...

CVE-2024-25653MEDIUM4.3ten sam produkt

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users,...