cognitive cybersecurity intelligence

News and Analysis

Search

High-severity vulnerability in Passwordstate credential manager. Patch now.

High-severity vulnerability in Passwordstate credential manager. Patch now.


The maker of Passwordstate, an enterprise-grade password manager for storing companies’ most privileged credentials, is urging them to promptly install an update fixing a high-severity vulnerability that hackers can exploit to gain administrative access to their vaults.
The authentication bypass allows hackers to create a URL that accesses an emergency access page for Passwordstate. From there, an attacker could pivot to the administrative section of the password manager. A CVE identifier isn’t yet available.
Safeguarding enterprises’ most privileged credentials
Click Studios, the Australia-based maker of Passwordstate, says the credential manager is used by 29,000 customers and 370,000 security professionals. The product is designed to safeguard organizations’ most privileged and sensitive credentials. Among other things, it integrates into Active Directory, the service Windows network admins use to create, change, and modify user accounts. It can also be used for handling password resets, event auditing, and remote session logins.Read full article
Comments

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

‘It Feels Like the CDC Is Over’

‘It Feels Like the CDC Is Over’

The Centers for Disease Control and Prevention is coming undone. The White House announced last night that it had ousted the agency’s newly sworn-in director,