A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17417 | A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services. |
Solution
Tenable has released Tenable Identity Exposure Secure Relay Version 3.59.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure https://www.tenable.com/downloads/identity-exposure
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2024-03 |
|
Tue, 17 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable identity Exposure |
|
| CPEs | cpe:2.3:a:tenable:identity_exposure:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tenable
Tenable identity Exposure |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T18:48:21.833Z
Reserved: 2024-02-20T19:24:25.274Z
Link: CVE-2024-1683
Updated: 2024-08-01T18:48:21.833Z
Status : Analyzed
Published: 2024-02-23T01:15:52.700
Modified: 2024-12-17T17:10:15.347
Link: CVE-2024-1683
No data.
OpenCVE Enrichment
No data.
EUVD