CVE-2025-56689: Medium severity Quest One Identity vulnerability
One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response. NOTE: this is disputed by the Supplier because, by design, the product successfully authenticates a client that possesses a cookie whose validity time interval includes the current time, and thus authentication after any type of "interception" is not a violation of the security model. (The cookie has the HttpOnly attribute.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56689?
CVE-2025-56689 has a high severity rating due to the potential for attackers to gain unauthorized access to the PAM portal.
What does CVE-2025-56689 affect?
CVE-2025-56689 affects Quest One Identity version 7.5.1.20903, specifically targeting its multifactor authentication process.
How do I fix CVE-2025-56689?
To mitigate CVE-2025-56689, it is recommended to upgrade to a patched version of Quest One Identity that addresses this vulnerability.
What is the impact of CVE-2025-56689?
The impact of CVE-2025-56689 allows attackers to bypass one-time password verification, potentially leading to unauthorized control over user accounts.
Is CVE-2025-56689 being actively exploited?
As of now, there have been reports of CVE-2025-56689 being exploited in the wild, heightening the urgency for affected users to apply security updates.