By LBT Technology Group, LLC. on Monday, 18 March 2024
Category: Security

OpenEdge authentication bypass vulnerability

Threat update

A critical vulnerability (CVE-2024-1403) affecting Progress Software OpenEdge Authentication Gateway and AdminServer impacts versions 11.7.18 and earlier, 12.2.13 and earlier, and 12.8.0. The vulnerability allows unauthorized access due to manipulation of username and password combinations during the authentication process. Review this Cybersecurity Threat Advisory to minimize the potential impact on your systems.

Technical Detail and Additional Info

What is the threat?

The vulnerability arises from the software's inability to validate certain username and password combinations. This weakness allows an attacker to bypass authentication checks and gain unauthorized access to protected systems.

The following OpenEdge versions are susceptible to CVE-2024-1403:

Why is it noteworthy?

The exploit targets a function called "connect()" within the AdminServer service responsible for handling remote connection attempts. By manipulating specific username and password combinations, the exploit bypasses authentication and grants unauthorized access.

What is the exposure or risk?

CVE-2024-1403 carries a maximum severity rating of 10.0 on the CVSS scoring system, indicating a critical vulnerability. An attacker can exploit this vulnerability to:

What are the recommendations?

 LBT Technology Group, LLC. recommends the following actions to limit the impact of CVE-2024-1403:

  1. Apply security patches. Update OpenEdge to the following versions:

     2. Disable any unnecessary OpenEdge services like the AdminServer to minimize the attack surface

     3. Implement network segmentation strategies to isolate critical systems and limit the potential impact of a successful attack.

     4. Monitor systems for suspicious activity and unauthorized access attempts.

References

 For more in-depth information about the recommendations, please visit the following links:

If you have any questions, please contact LBT's Sales Engineer.

Related Posts

Leave Comments