MEDIUM🇵🇱 Wersja polska

CVE-2024-25650

CVSS 5.9v3.1pub. 2024-03-14upd. 2025-10-10

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Delinea Distributed Engine

    APP
    Delinea
    8.4.3
  • Delinea Secret Server

    APP
    Delinea
    11.4.000000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-4589CRITICAL9.1PL ✓same product

Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji

CVE-2024-33891HIGH8.8same product

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...

CVE-2024-25652HIGH7.6same product

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...

CVE-2025-12810MEDIUM5.3same product

Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...

CVE-2024-12908MEDIUM6.9same product

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...