CVE-2024-9313

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Oct 4, 2024

Summary

CVE-2024-9313 is a newly disclosed vulnerability affecting the Authd PAM module before version 0.3.5. This issue permits broker-managed users to assume the identity of any other user controlled by the same broker. As a result, these users can carry out any PAM (Pluggable Authentication Modules) operation, including authenticating as the targeted user. This security flaw poses a significant risk, as it enables unauthorized access and potential privilege escalation. System administrators are advised to upgrade their Authd PAM module to the latest version to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share