CRITICAL🇵🇱 Wersja polska

CVE-2024-49805

CVSS 9.4v3.1pub. 2024-11-29upd. 2025-01-29

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

🤖 AI Analysis
How it works

The application stores hard-coded credentials (CWE-798) in its code or configuration, which are used for incoming authentication, outgoing communication with external components, or encryption of internal data. Since the values of these credentials are identical across all product installations, anyone who learns their content — for example through software analysis or a leak — can use them directly. The attacker does not need to possess any privileges or require user interaction, and the attack is possible remotely over the network.

Impact

An attacker can gain unauthorized access to the device or related components, leading to a breach of data confidentiality and integrity, and in specific scenarios also partial loss of service availability.

Mitigation & patch

Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7177447. It is recommended to update immediately to a version beyond 10.0.8 and — until the patch is deployed — restrict network access to the device only to trusted hosts using firewall and network segmentation.

Who is affected

IBM Security Verify Access Appliance in versions 10.0.0 to 10.0.8 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • IBM Security Verify Access

    APP
    Ibm
    10.0.0 – 10.0.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-1346CRITICAL9.3PL ✓same product

Privilege escalation do root w IBM Security Verify Access i Verify Identity Access

CVE-2025-36356CRITICAL9.3PL ✓same product

IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia

CVE-2024-49806CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49803CRITICAL9.8PL ✓same product

IBM Security Verify Access — zdalne wykonanie poleceń (command injection)

CVE-2021-39070CRITICAL9.8PL ✓same product

IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik