CVE-2024-5813
MEDIUMCVSS 4.9/10EPSS 0.41%
Last modified
CVE-2024-5813 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Beyondtrust | Beyondinsight Password Safe | >= 23.3, < 23.3.0.929 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5813?
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
How severe is CVE-2024-5813?
CVE-2024-5813 has a CVSS score of 4.9/10 (MEDIUM severity). The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2024-5813?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-58124Access control vulnerability in the security verification mo…9.1
- CVE-2024-58125Access control vulnerability in the security verification mo…9.1
- CVE-2024-58126Access control vulnerability in the security verification mo…9.1
- CVE-2024-58127Access control vulnerability in the security verification mo…9.1
- CVE-2024-58128In MISP before 2.4.193, menu_custom_right_link parameters ca…4.8
- CVE-2024-58129In MISP before 2.4.193, menu_custom_right_link_html paramete…4.8
- CVE-2024-58130In app/Controller/Component/RestResponseComponent.php in MIS…6.1
- CVE-2024-58131FISCO BCOS 3.11.0 has an issue with synchronization of the t…3.7
- CVE-2024-58132In chainmaker-go (aka ChainMaker) before 2.3.6, multiple upd…4
- CVE-2024-58133In chainmaker-go (aka ChainMaker) before 2.4.0, when making …4
- CVE-2024-58134Mojolicious versions from 0.999922 for Perl uses a hard code…8.1
- CVE-2024-58135Mojolicious versions from 7.28 through 9.45 for Perl will ge…5.3
Are you affected by CVE-2024-5813?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
