CVE-2024-50618

A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a single-factor authentication scheme gets compromised.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

History

17 Jun 2026, 08:04

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de uso de autenticación de un solo factor en el componente de autenticación de CIPPlanner CIPAce anterior a 9.17 permite a los atacantes eludir un mecanismo de protección. Cuando el sistema está configurado para permitir el inicio de sesión con cuentas internas, un atacante puede posiblemente obtener autenticación completa si el secreto en un esquema de autenticación de un solo factor se ve comprometido.

17 Feb 2026, 15:01

Type Values Removed Values Added
References () https://cipplanner.com/cve-2024-50618-cve-public-notification-of-resolution/ - () https://cipplanner.com/cve-2024-50618-cve-public-notification-of-resolution/ - Vendor Advisory
First Time Cipplanner cipace
Cipplanner
CPE cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:*

12 Feb 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-308

11 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 20:16

Updated : 2026-06-17 08:04


NVD link : CVE-2024-50618

Mitre link : CVE-2024-50618

CVE.ORG link : CVE-2024-50618


JSON object : View

Products Affected

cipplanner

  • cipace
CWE
CWE-308

Use of Single-factor Authentication