Medium severity5.9NVD Advisory· Published Mar 14, 2024· Updated Jun 17, 2026
CVE-2024-25650
CVE-2024-25650
Description
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:delinea:distributed_engine:8.4.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:delinea:distributed_engine:8.4.3:*:*:*:*:*:*:*
- (no CPE)range: 8.4.3
- cpe:2.3:a:delinea:secret_server:11.4.000000:*:*:*:on-premises:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 11.4
Patches
Vulnerability mechanics
References
1- www.cvcn.gov.it/cvcn/cve/CVE-2024-25650nvdThird Party Advisory
News mentions
0No linked articles in our index yet.