CVE-2024-45673

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7183801 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

18 Jun 2025, 23:36

Type Values Removed Values Added
Summary
  • (es) IBM Security Verify Bridge Directory Sync 1.0.1 a 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 a 1.0.10 e IBM Security Verify Gateway for Radius 1.0.1 a 1.0.11 almacenan las credenciales de usuario en archivos de configuración que pueden ser leídos por un usuario local.
First Time Linux
Ibm security Verify Gateway For Radius
Microsoft
Ibm
Ibm security Verify Gateway For Windows Login
Microsoft windows
Ibm security Verify Bridge Directory Sync
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7183801 - () https://www.ibm.com/support/pages/node/7183801 - Vendor Advisory

21 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 17:15

Updated : 2025-06-18 23:36


NVD link : CVE-2024-45673

Mitre link : CVE-2024-45673

CVE.ORG link : CVE-2024-45673


JSON object : View

Products Affected

microsoft

  • windows

ibm

  • security_verify_gateway_for_windows_login
  • security_verify_bridge_directory_sync
  • security_verify_gateway_for_radius

linux

  • linux_kernel
CWE
CWE-260

Password in Configuration File