Zach Hanley, Horizon3ai Chief Attack Engineer, has just published CVE-2024-1403: Progress OpenEdge Authentication Bypass Deep-Dive, a deep dive with a proof of concept link and indicators of compromise on the vuln in Progress Software’s OpenEdge application development suite.
The post follows the February 27, 2024, security advisory Progress issued for OpenEdge, their application development and deployment platform suite, warning of an auth bypass vuln impacting some platform components, stemming from a failure to properly handle username and password. Certain unexpected content passed into the credentials enables unauthorized access without authentication.
The Progress advisory linked below notes: “When the OpenEdge Authentication Gateway (OEAG) is configured with an OpenEdge Domain that uses the OS local authentication provider to grant user-id and password logins on operating platforms supported by active releases of OpenEdge, a vulnerability in the authentication routines may lead to unauthorized access on attempted logins. Similarly, when an AdminServer connection is made by OpenEdge Explorer (OEE) and OpenEdge Management (OEM), it also utilizes the OS local authentication provider on supported platforms to grant user-id and password logins that may also lead to unauthorized login access.”
Links:
- Blog – CVE-2024-1403: Progress OpenEdge Authentication Bypass Deep-Dive: https://www.horizon3.ai/attack-research/cve-2024-1403-progress-openedge-authentication-bypass-deep-dive/
- Horizon3.ai Proof of Concept on GitHib – CVE-2024-1403 Progress OpenEdge Authentication Bypass: https://github.com/horizon3ai/CVE-2024-1403
- Progress Software February 27, 2024 advisory – Important Security Update for OpenEdge Authentication Gateway and AdminServer: https://community.progress.com/s/article/Important-Critical-Alert-for-OpenEdge-Authentication-Gateway-and-AdminServer
- NIST CVE-2024-1403 Detail: https://nvd.nist.gov/vuln/detail/CVE-2024-1403
- Progress Software OpenEdge: https://www.progress.com/openedge

LinkedIn Takes A Dirt Nap [UPDATE: Fixed]
Posted in Commentary with tags LinkedIn on March 6, 2024 by itnerdFor the second straight day, we have an online service that has fallen and can’t get up. This time it’s LinkedIn. This is what my LinkedIn app looks like at the moment:
And Down Detector confirms that they have issues:
You will also note that Twitter and Facebook apparently have issues. I can’t find any evidence that Twitter has issues. Though given Twitter’s track record under Elon Musk, it would not be a shock if they did. I also don’t see evidence that Facebook is currently down. But they were down 24 hours ago so who knows. In any case, I’ll be watching this and providing updates when there are any.
UPDATE: This is now fixed.
Leave a comment »