Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31595 | Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute. |
Tue, 28 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:delinea:secret_server:*:*:*:*:on-premises:*:*:* |
Wed, 12 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Delinea
Delinea secret Server |
|
| CPEs | cpe:2.3:a:delinea:secret_server:10.9.000002:*:*:*:*:*:*:* | |
| Vendors & Products |
Delinea
Delinea secret Server |
|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-12T14:59:33.572Z
Reserved: 2024-04-28T00:00:00.000Z
Link: CVE-2024-33891
Updated: 2024-08-02T02:42:59.716Z
Status : Analyzed
Published: 2024-04-28T23:15:07.200
Modified: 2025-10-28T18:50:31.543
Link: CVE-2024-33891
No data.
OpenCVE Enrichment
No data.
EUVD