CVE-2024-45551

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Apr 7, 2025
CWE ID 1390

Summary

CVE-2024-45551 is a newly identified cryptographic vulnerability that affects the Gatekeeper software during PIN/password verification. The issue arises when RPMB (Root Protection Module Database) write operations are dropped upon verification failure, which could potentially enable bypassing user throttling. This vulnerability poses a significant risk as it can undermine the security measures intended to limit the number of login attempts, making it easier for unauthorized users to gain access to protected systems. Organizations using Gatekeeper are advised to apply the necessary patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share