Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19814 | Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs). |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-27T15:18:28.113Z
Reserved: 2024-01-08T18:43:03.535Z
Link: CVE-2024-22245
Updated: 2024-08-01T22:43:34.194Z
Status : Deferred
Published: 2024-02-20T18:15:51.647
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-22245
No data.
OpenCVE Enrichment
No data.
EUVD