Online Tools Directory

Netwrix PingCastle Vulnerabilities Fixed in Version 3.3.0.1

Discover critical Netwrix PingCastle Pro/Enterprise vulnerabilities fixed in version 3.3.0.1. Update now to secure your system and data.
Netwrix PingCastle Vulnerabilities Fixed in Version 3.3.0.1
Netwrix PingCastle Vulnerabilities Fixed in Version 3.3.0.1

In November 2024, several security vulnerabilities were identified in Netwrix PingCastle Pro and Enterprise editions. These vulnerabilities could potentially allow unauthorized access or disrupt the application's availability. Netwrix has addressed these issues in version 3.3.0.1, released on September 25, 2024.

Identified Vulnerabilities

  1. Broken Authentication – API Key State Ignored: Disabled API keys were still permitting access, potentially allowing unauthorized entry. This vulnerability received a CVSS 3.1 score of 6.5.
  2. Account Policy – Weak Lockout Policy: The absence of an account lockout policy increased the risk of dictionary attacks on user accounts without Multi-Factor Authentication (MFA). This issue was assigned a CVSS 3.1 score of 7.1.
  3. Denial of Service – Shared Resource Lock: A shared resource intended to prevent brute-force attacks on account recovery codes could be exploited to execute a Denial-of-Service (DoS) attack, rendering the application unavailable during the attack. This vulnerability had a CVSS 3.1 score of 4.6.
  • Update to the Latest Version: Users of Netwrix PingCastle Pro and Enterprise editions should upgrade to version 3.3.0.1 or later to mitigate these vulnerabilities.
  • Review Security Configurations: Ensure that API keys are managed appropriately, account lockout policies are enforced, and shared resources are secured to prevent potential exploitation.

Source: https://borncity.com/win/2024/11/18/vulnerabilities-in-netwrix-pingcastle-pro-enterprise-nov-2024/

About the author
Decoge

Decoge

Decoge is a tech enthusiast with a keen eye for the latest in technology and digital tools, writing reviews and tutorials that are not only informative but also accessible to a broad audience.

Online Tools Directory

Discover the Online Tools Directory, your ultimate resource for top digital tools. Enhance productivity, foster collaboration, and achieve business success. Subscribe for updates!

Online Tools Directory

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Online Tools Directory.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.