← All CVEs

CVE-2024-45488

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

9.8
CVSS
50.6%
EPSS (exploit prob.)
99th
EPSS percentile
2024-08-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-45488