One Identity by Quest Safeguard for Privileged Passwords...
Moderate severity
Unreviewed
Published
Sep 8, 2025
to the GitHub Advisory Database
•
Updated Sep 8, 2025
Description
Published by the National Vulnerability Database
Sep 3, 2025
Published to the GitHub Advisory Database
Sep 8, 2025
Last updated
Sep 8, 2025
One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.
References