CRITICAL🇵🇱 Wersja polska

CVE-2023-4589

CVSS 9.1v3.1pub. 2023-09-06upd. 2024-11-21

Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process lacks digital signatures and fails to validate the integrity of the update package, allowing the attacker to inject malicious applications during the update.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Delinea Secret Server

    APP
    Delinea
    10.9.000002
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-33891HIGH8.8same product

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2024-25652HIGH7.6same product

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...

CVE-2025-12810MEDIUM5.3same product

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...

CVE-2024-12908MEDIUM6.9same product

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...

CVE-2024-25650MEDIUM5.9same product

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM adm...