**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.gruppotim.it/it/footer/red-team.html | Third Party Advisory | 
Configurations
                    History
                    14 Oct 2025, 18:04
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Bmc remedy Mid-tier Bmc | |
| CPE | cpe:2.3:a:bmc:remedy_mid-tier:7.6.04:*:*:*:*:*:*:* | |
| References | () https://www.gruppotim.it/it/footer/red-team.html - Third Party Advisory | 
20 Sep 2024, 12:30
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
18 Sep 2024, 19:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
| CWE | CWE-287 | 
18 Sep 2024, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-09-18 18:15
Updated : 2025-10-14 18:04
NVD link : CVE-2024-34399
Mitre link : CVE-2024-34399
CVE.ORG link : CVE-2024-34399
JSON object : View
Products Affected
                bmc
- remedy_mid-tier
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
