
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
The vulnerability (CVE-2024-9191) affects the Okta Device Access features in Okta Verify agent for Windows. Discovered through routine penetration testing, this high-severity vulnerability allows attackers on a compromised device to retrieve passwords associated with Desktop MFA passwordless logins through the OktaDeviceAccessPipe. The vulnerability specifically impacts versions 5.0.2 to 5.3.2 of Okta Verify for Windows, but only affects users who have enabled the Okta Device Access passwordless feature (NVD, Security Online).
The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High) by NIST and 7.1 (High) by Okta. The CVSS vector string is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access requirements, low attack complexity, and high impacts on confidentiality, integrity, and availability. The vulnerability is classified under CWE-276 (Incorrect Default Permissions) (NVD).
If exploited, the vulnerability allows attackers who have already compromised a device to access passwords stored for Desktop MFA passwordless logins. This could potentially lead to unauthorized access to the user's Okta account and any connected applications (Security Online).
Okta has released version 5.3.3 of Okta Verify for Windows to address this vulnerability. Users running versions 5.0.2 to 5.3.2 are strongly advised to upgrade immediately to the latest version (Security Online).
The vulnerability was discovered through routine penetration testing by Anvil Secure, who has been credited in Okta's advisory (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”