Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-10327

8.1 · HIGH
Published Oct 24, 2024 CWE-287 EPSS 0.56% (44th pctl)

Overview

CVE-2024-10327 is a high-severity vulnerability. It was published on October 24, 2024 and has a CVSS 3.1 base score of 8.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed.

The ContextExtension feature is one of several push mechanisms available when using Okta Verify Push on iOS devices. The vulnerable flows include:

* When a user is presented with a notification on a locked screen, the user presses on the notification directly and selects their reply without unlocking the device;

* When a user is presented with a notification on the home screen and drags the notification down and selects their reply;

* When an Apple Watch is used to reply directly to a notification.

A pre-condition for this vulnerability is that the user must have enrolled in Okta Verify while the Okta customer was using Ok

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2024-10327?

CVE-2024-10327 is a high-severity vulnerability. It was published on October 24, 2024 and has a CVSS 3.1 base score of 8.1 (HIGH).

How severe is CVE-2024-10327?

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-10327?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-10327?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-10327 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.