10th June 2024
SecurEnvoy MFA CVE-2024-37393
#securenvoy #2fa #zerotrust #vulnerability #ldap #injection #activedirectory
Optistream identified critical vulnerabilities within SecurEnvoy MFA 9.4.513, a widely used Zero Trust solution that provides two-factor authentication (2FA) to third-party softwares.
Optistream responsibly disclosed the issues to the vendor and helped at fixing them. We present a detailed workthrough of our study in the attacker point of view.