Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37510 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 19 Dec 2024 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 | |
| Metrics |
cvssV3_1
|
Tue, 17 Dec 2024 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands. | |
| Title | Improper Privilege Management Vulnerability in CA Client Automation 14.5 | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2024-12-19T06:03:39.527Z
Reserved: 2024-06-18T06:18:01.976Z
Link: CVE-2024-38499
Updated: 2024-12-19T06:03:39.527Z
Status : Deferred
Published: 2024-12-17T06:15:20.760
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-38499
No data.
OpenCVE Enrichment
No data.
EUVD