MEDIUM🇵🇱 Wersja polska

CVE-2024-25649

CVSS 6.7v3.1pub. 2024-03-14upd. 2025-11-13

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
  • Delinea Secret Server

    APP
    Delinea
    11.4.000000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-4589CRITICAL9.1PL ✓same product

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8same product

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2024-25652HIGH7.6same product

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...

CVE-2025-12810MEDIUM5.3same product

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...

CVE-2024-12908MEDIUM6.9same product

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...