Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability
ID: a4de4aa6-913b-5e03-be9b-05cc0ec7836f
STIX ID: report--a4de4aa6-913b-5e03-be9b-05cc0ec7836f
Feed Name: The Hacker News
A critical authentication bypass (CVE-2024-1403) in Progress OpenEdge Authentication Gateway and AdminServer can incorrectly return authentication success for certain malformed credentials, enabling unauthorized access; the flaw affects several OpenEdge versions, has a CVSS of 10.0, and Horizon3.ai published a PoC. Progress released patched updates (11.7.19, 12.2.14, 12.8.1) and researchers note the potential for further exploitation including possible remote code execution with additional research.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
