HomeSecurityIBM Security: Vulnerability allows execution of arbitrary commands

IBM Security: Vulnerability allows execution of arbitrary commands

IBM has identified and disclosed multiple critical vulnerabilities affecting the Security Verify Access Appliance, exposing users to serious security risks.

IBM Security

Vulnerability Details

The vulnerabilities identified include:

  • CVE-2024-49803
  • CVE-2024-49804
  • CVE-2024-49805
  • CVE-2024-49806

These vulnerabilities affect versions 10.0.0 through 10.0.8 IF1 of the device. The most severe, CVE-2024-49803, was rated with a CVSS base score of 9.8, indicating a critical risk. According to IBM researchers, this vulnerability could allow a remote, authenticated attacker to execute arbitrary commands on the system, leveraging a specially crafted request.

See also: IBM Engineering Systems flaw allows bypass of security restrictions

Technical Analysis

The CVE-2024-49803 results from inadequate handling of special characters in operating system commands, making the device vulnerable to injection.

Additionally, two other critical vulnerabilities, CVE-2024-49805 and CVE-2024-49806, rated with a CVSS score of 9.4, are associated with the use of hard-coded credentials. These credentials, such as passwords or cryptographic keys, are used for authentication, external communications, or data encryption, increasing the risk of unauthorized access and data leakage.

The fourth vulnerability, CVE-2024-49804, with a CVSS score of 7.8, allows a locally authenticated non-administrative user to escalate privileges by exploiting unnecessary permissions on specific functions. Although less severe, it still compromises system integrity.

Read more: Vulnerability in Atlassian Sourcetree allows code execution

Suggested Solutions

IBM vulnerability

IBM has released a fix to address these vulnerabilities via patch version 10.0.8-ISS-ISVA-FP0002. Users of affected versions are urged to install the patchto reduce the risk of potential attacks.

At this time, there are no known ways to mitigate these vulnerabilities beyond applying this patch. Users are encouraged to remain vigilant and take proactive measures to ensure the security of their systems.

See also: D-Link: Recommends replacing old VPN routers due to vulnerability

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS