CVE-2024-21638
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-21638 is a vulnerability affecting Azure IPAM (IP Address Management), a solution designed to help manage IP address spaces on the Azure platform. Despite the Service Principal being only assigned the Reader role at the root Management Group level, the solution did not validate authentication tokens, leaving it susceptible to token impersonation attacks. Successful exploitation of this vulnerability could allow an attacker to impersonate any privileged user and gain access to sensitive data stored within the IPAM instance as well as from Azure, resulting in a significant elevation of privilege. This issue has been addressed in version 3.0.0 of Azure IPAM.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.