CVE-2024-45673

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7183801 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 Jun 2025, 23:36

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
Summary
  • (es) IBM Security Verify Bridge Directory Sync 1.0.1 a 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 a 1.0.10 e IBM Security Verify Gateway for Radius 1.0.1 a 1.0.11 almacenan las credenciales de usuario en archivos de configuración que pueden ser leídos por un usuario local.
References () https://www.ibm.com/support/pages/node/7183801 - () https://www.ibm.com/support/pages/node/7183801 - Vendor Advisory
First Time Ibm
Ibm security Verify Bridge Directory Sync
Linux
Ibm security Verify Gateway For Windows Login
Linux linux Kernel
Microsoft windows
Microsoft
Ibm security Verify Gateway For Radius

21 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 17:15

Updated : 2025-06-18 23:36


NVD link : CVE-2024-45673

Mitre link : CVE-2024-45673

CVE.ORG link : CVE-2024-45673


JSON object : View

Products Affected

microsoft

  • windows

ibm

  • security_verify_gateway_for_windows_login
  • security_verify_gateway_for_radius
  • security_verify_bridge_directory_sync

linux

  • linux_kernel
CWE
CWE-260

Password in Configuration File