← back
CVE-2024-21638

Azure IPAM solution Elevation of Privilege Vulnerability

CVSS 9.1 CRITICALEPSS 1.7%CWE-269
In short

Azure IPAM failed to validate authentication tokens, allowing attackers to impersonate any user and access sensitive IP address data and Azure environment information. This bypasses the intended read-only restrictions and can lead to unauthorized access to critical infrastructure.

Technical detail

The vulnerability stems from insufficient authentication token validation (CWE-269) in Azure IPAM, enabling token forgery or replay attacks where an attacker can impersonate privileged users to extract IP address management data and potentially perform unauthorized Azure resource enumeration. The Service Principal's Reader role at root Management Group level is intended as a mitigation, but lacks effect when authentication controls are bypassed at the application layer.

Summary generated and translated by AI from the official description.
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal used is only assigned the Reader role at the root Management Group level. Until recently, the solution lacked the validation of the passed in authentication token which may result in attacker impersonating any privileged user to access data stored within the IPAM instance and subsequently from Azure, causing an elevation of privilege. This vulnerability has been patched in version 3.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Azure · ipam

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →