CVE-2024-21638

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 10, 2024
Updated: Jan 19, 2024
CWE ID 287
CWE ID 269

Summary

CVE-2024-21638 is a vulnerability affecting Azure IPAM (IP Address Management), a solution designed to help manage IP address spaces on the Azure platform. Despite the Service Principal being only assigned the Reader role at the root Management Group level, the solution did not validate authentication tokens, leaving it susceptible to token impersonation attacks. Successful exploitation of this vulnerability could allow an attacker to impersonate any privileged user and gain access to sensitive data stored within the IPAM instance as well as from Azure, resulting in a significant elevation of privilege. This issue has been addressed in version 3.0.0 of Azure IPAM.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-21638 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions