Horizon Alert
Summary of the vulnerability and why it matters
An authentication flaw has been identified in Claroty Secure Access, potentially allowing unauthorized user creation or impersonation. This could enable attackers to gain access to systems or act as legitimate users. The main concern is confirming relevance and exposure to your environment.
- Flaw lets unauthorized users create accounts or impersonate others.
- Could allow unauthorized access to your critical systems.
- Confirm if Claroty Secure Access is in use and exposed.
Attack Path
How an attacker could exploit the issue
An attacker could exploit an issue in how Claroty Secure Access handles authentication requests. If an attacker can send specially crafted requests to the system, they might be able to create new user accounts or take over existing ones, potentially gaining unauthorized access to sensitive information or functionality.
- No authentication required to reach the vulnerability.
- Vulnerable OIDC authentication flow can be triggered.
- Unauthorized user creation or impersonation risk.
Live Threat
Current exploitation, exposure, and threat context
The incorrect OpenID Connect (OIDC) authentication flow in Claroty Secure Access could allow an attacker to create unauthorized users or impersonate existing ones. This could occur when the system is configured to use OIDC for authentication, potentially affecting user access and system integrity.
- Unauthorized user creation or impersonation.
- Exploiting misconfigured OIDC authentication.
- Compromised user access and system integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Claroty Secure Access, a product likely managed by infrastructure or platform teams responsible for secure remote access. The immediate priority is to identify all instances of the affected technology, assess their exposure and business criticality, and locate the accountable asset owner to coordinate a risk-based remediation plan.
- Own the issue: Infrastructure/Platform Teams.
- Verify first: System reachability and criticality.
- Action: Plan coordinated remediation.