CVE-2025-56689

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.
Configurations

No configuration.

History

08 Sep 2025, 16:15

Type Values Removed Values Added
Summary (en) An issue was discovered in Quest One Identity 7.5.1.20903. A crafted response manipulation can bypass the OTP on MFA page which leads to access the PAM portal without OTP allowing attackers to control an arbitrary account. (en) One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.

03 Sep 2025, 20:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

03 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-03 17:15

Updated : 2025-09-08 16:15


NVD link : CVE-2025-56689

Mitre link : CVE-2025-56689

CVE.ORG link : CVE-2025-56689


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing