CVE-2024-28058
In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28058?
CVE-2024-28058 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-28058?
To remediate CVE-2024-28058, upgrade to RSA NetWitness Platform version 12.5.1 or later, where this flaw is addressed.
Who is affected by CVE-2024-28058?
CVE-2024-28058 affects all installations of RSA NetWitness Platform prior to version 12.5.1.
What type of vulnerability is CVE-2024-28058?
CVE-2024-28058 is a broken access control vulnerability that allows internal threat actors to impersonate revoked users.
What are the potential impacts of CVE-2024-28058?
The potential impact of CVE-2024-28058 includes unauthorized access to sensitive data, leading to data breaches and compromised system integrity.