vendor:
CyberArk Privileged Session Manager SSH Proxy (PSMP)
by:
LAHBAL Said
N/A
CVSS
N/A
Policy Restriction Bypass
Unknown
CWE
Product Name: CyberArk Privileged Session Manager SSH Proxy (PSMP)
Affected Version From: PSMP <=10.9.1
Affected Version To: PSMP >= 11.1
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: PSMP 10.9 & PSMP 10.9.1
2020
CyberArk PSMP 10.9.1 – Policy Restriction Bypass
All recordings mechanisms (Keystoke, SSH Text Recorder and video) can be evaded because users entries are not properly validated. Commands executed in a reverse shell are not monitored. The connection process will freeze just after the 'session is being recorded' banner and the all commands we enter are not monitored.
Mitigation:
Patched version PSMP >= 11.1 should be installed