CRITICAL🇵🇱 Wersja polska

CVE-2024-49806

CVSS 9.4v3.1pub. 2024-11-29upd. 2025-01-29

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

🤖 AI Analysis
How it works

The vulnerability consists of the presence of static, hard-coded credentials (CWE-798) in the software that can be used for incoming authentication, communication with external components, or encryption of internal data. An attacker who learns these credentials (e.g., through software analysis) can use them to gain access to the device or systems communicating with it. Since the attack requires no authentication or user interaction, and the attack vector is network-based, the barrier to entry is very low.

Impact

An attacker can gain unauthorized access to the system, take control of protected data, or disrupt the operation of security infrastructure components, leading to violations of data confidentiality and integrity.

Mitigation & patch

Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7177447

Who is affected

IBM Security Verify Access Appliance in versions 10.0.0 through 10.0.8 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • IBM Security Verify Access

    APP
    Ibm
    10.0.0 – 10.0.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-1346CRITICAL9.3PL ✓same product

Privilege escalation do root w IBM Security Verify Access i Verify Identity Access

CVE-2025-36356CRITICAL9.3PL ✓same product

IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia

CVE-2024-49805CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49803CRITICAL9.8PL ✓same product

IBM Security Verify Access — zdalne wykonanie poleceń (command injection)

CVE-2021-39070CRITICAL9.8PL ✓same product

IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik