IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
CVE ID: CVE-2024-45673
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.5
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor: IBM
Product: Security Verify Bridge Directory Sync
EPSS Score: 0.01% (probability of being exploited)
EPSS Percentile: 0.59% (scored less or equal to compared to others)
EPSS Date: 2025-03-22 (when was this score calculated)