Patch this critical Safeguard for Privileged Passwords auth bypass flaw (CVE-2024-45488) – Help Net Security

Summary: Researchers have disclosed a critical authentication bypass vulnerability, CVE-2024-45488, in One Identity’s Safeguard for Privileged Passwords (SPP), potentially allowing attackers full administrative access. The vulnerability arises from a hard-coded cryptographic key, enabling attackers to forge session cookies and manipulate the appliance.

Threat Actor: Unknown | unknown
Victim: One Identity | One Identity

Key Point :

  • CVE-2024-45488 allows attackers to gain administrative access to the SPP virtual appliance.
  • Attackers can reconfigure settings, modify policies, and extract passwords from managed accounts.
  • The vulnerability affects only SPP hosted on VMware or HyperV, not on physical appliances or supported cloud platforms.
  • Users are advised to upgrade to specific versions to mitigate the vulnerability.
  • A script has been released to help users check if their instance is vulnerable.

Researchers have released technical details about CVE-2024-45488, a critical authentication bypass vulnerability affecting One Identity’s Safeguard for Privileged Passwords (SPP), which could allow attackers to gain full administrative access to the virtual appliance.

CVE-2024-45488

“Once an attacker has gained an authenticated administrative session on the appliance, they can carry out any action that a legitimate administrator user would be capable of. This includes the ability to reconfigure settings on the appliance, or modify policies to allow extraction of passwords stored in managed accounts or personal vaults,” AmberWolf researchers have explained.

“If the appliance is configured to use the default backup encryption setting (which uses a hardcoded RSA key), then the attacker can also download and decrypt a copy of any appliance backups.”

About CVE-2024-45488

One Identity Safeguard for Privileged Passwords is a solution that “automates, controls and secures the process of granting privileged credentials with role-based access management and automated work flows.”

CVE-2024-45488 (aka “Skeleton Cookie”) arises from the presence of a hard-coded cryptographic key in SPP virtual appliance images, which could be used by attackers to forge session cookies.

The easy-to-understand write-up by researchers David Cash and Richard Warren details the discovery of the vulnerability and includes a video demo of their exploit in action.

Is your virtual appliance vulnerable?

After the researchers shared their findings, One Identity confirmed that the vulnerability does not impact deployments running on physical appliances, hosted in Azure, AWS, OCI or other officially supported cloud platforms – just Safeguard for Privileged Passwords hosted on VMware or HyperV.

Users have been advised to upgrade to Safeguard for Privileged Passwords 7.0.5.1 LTS, 7.4.2 or 7.5.2, which contain the fix.

AmberWolf researchers have also released a script users can check whether their instance is vulnerable to CVE-2024-45488 exploitation.


Source: https://www.helpnetsecurity.com/2024/09/19/cve-2024-45488