CVE-2024-5812: Smart Rule Overwrite Bypass in BeyondInsight PasswordSafe
Published Jun 11, 2024
·Updated
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Affected Software
4 affected components
BeyondTrust BeyondInsight PasswordSafe
BeyondTrust Beyondinsight Password Safe>=23.2<23.2.0.1293
BeyondTrust Beyondinsight Password Safe>=23.3<23.3.0.959
BeyondTrust Beyondinsight Password Safe=24.1
Event History
Jun 11, 2024
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5812?
CVE-2024-5812 is classified as a low severity vulnerability.
2
How does CVE-2024-5812 impact BIPS?
CVE-2024-5812 allows an attacker with high privileges to overwrite Read-Only smart rules via a specially crafted API request.
3
What versions of BIPS are affected by CVE-2024-5812?
CVE-2024-5812 affects BeyondTrust BeyondInsight PasswordSafe versions up to 23.2.0.1293, 23.3.0.959, and 24.1.
4
How can I mitigate CVE-2024-5812?
To mitigate CVE-2024-5812, ensure that only authorized users have high privilege accounts.
5
Is a patch available for CVE-2024-5812?
As of now, please consult your BeyondTrust support representative for patch availability regarding CVE-2024-5812.