peter bassill · operator
$ cve CVE-2024-45488 JSON

CVE-2024-45488

9.8
CRITICAL · CVSS 3.1 · EPSS 50.6% (pctl 99)

Patch early

EPSS 50.6% — above the 10% action threshold.

Description

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS50.6% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploitnone known
Published2024-08-30
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD