The distributed engine versions 8.4.39.0 and earlier of Secret Server...
Vulnerability Description
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6942
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- NCIA researchers
References
- https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000060.htm
- https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000061.htm
- https://docs.delinea.com/online-help/secret-server-changelog/secret-server-change-log.htm?cshid=secret-server-changelog#Friday,_November_22,_2024
- https://trust.delinea.com/?tcuUid=2b68edca-7930-438d-b960-2d6da07cdde9
More from Delinea
View All →Affected Vendor
Delinea
View all reports →