CVE-2024-21638

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 10, 2024
Updated: Jan 19, 2024
CWE ID 287
CWE ID 269

Summary

CVE-2024-21638 is a vulnerability affecting Azure IPAM (IP Address Management), a solution designed to help manage IP address spaces on the Azure platform. Despite the Service Principal being only assigned the Reader role at the root Management Group level, the solution did not validate authentication tokens, leaving it susceptible to token impersonation attacks. Successful exploitation of this vulnerability could allow an attacker to impersonate any privileged user and gain access to sensitive data stored within the IPAM instance as well as from Azure, resulting in a significant elevation of privilege. This issue has been addressed in version 3.0.0 of Azure IPAM.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share