Advisory ID: BT24-08
CVSSv3 Score: 5.9
Severity: Medium
Issue Date: 2024-06-11
CVE: CVE-2024-5813
Summary
A medium severity vulnerability in BeyondInsight Password Safe has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
Affected Versions
Product | Version |
|---|---|
BeyondInsight Password Safe | 23.3 versions before the .929 hotfix |
Fixed Versions
Product | Version |
|---|---|
BeyondInsight Password Safe | 24.1 and later |
BeyondInsight Password Safe | 23.3.0.929 and later |
Acknowledgements
BeyondTrust would like to acknowledge Christian Dölling for reporting this issue.
