External risk intelligence

Claroty Secure Access OIDC Authentication Bypass Leading to Unauthorized User Creation

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-54603

Claroty Secure Access is designed as a remote access and gateway solution, which is inherently intended to be public-facing to provide secure connectivity for external users and remote workers.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authentication flaw has been identified in Claroty Secure Access, potentially allowing unauthorized user creation or impersonation. This could enable attackers to gain access to systems or act as legitimate users. The main concern is confirming relevance and exposure to your environment.

  • Flaw lets unauthorized users create accounts or impersonate others.
  • Could allow unauthorized access to your critical systems.
  • Confirm if Claroty Secure Access is in use and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit an issue in how Claroty Secure Access handles authentication requests. If an attacker can send specially crafted requests to the system, they might be able to create new user accounts or take over existing ones, potentially gaining unauthorized access to sensitive information or functionality.

  • No authentication required to reach the vulnerability.
  • Vulnerable OIDC authentication flow can be triggered.
  • Unauthorized user creation or impersonation risk.

Live Threat

Current exploitation, exposure, and threat context

The incorrect OpenID Connect (OIDC) authentication flow in Claroty Secure Access could allow an attacker to create unauthorized users or impersonate existing ones. This could occur when the system is configured to use OIDC for authentication, potentially affecting user access and system integrity.

  • Unauthorized user creation or impersonation.
  • Exploiting misconfigured OIDC authentication.
  • Compromised user access and system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Claroty Secure Access, a product likely managed by infrastructure or platform teams responsible for secure remote access. The immediate priority is to identify all instances of the affected technology, assess their exposure and business criticality, and locate the accountable asset owner to coordinate a risk-based remediation plan.

  • Own the issue: Infrastructure/Platform Teams.
  • Verify first: System reachability and criticality.
  • Action: Plan coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Claroty Secure Access?

Claroty Secure Access is a remote access gateway platform designed to provide secure connectivity for external users, contractors, and remote workers to critical industrial or enterprise environments. It serves as an intermediary bridge that allows authorized personnel to reach internal resources without exposing those systems directly to the public internet.

What does CVE-2025-54603 mean for authentication security?

This vulnerability is classified as CWE-284, which deals with Improper Access Control. Specifically, the OIDC authentication flow within the product does not correctly validate identity assertions. This means the system can be tricked into accepting forged authentication requests, allowing an unauthorized person to create a new user account or masquerade as an existing legitimate user.

How can an attacker trigger this authentication bypass?

An attacker triggers this by sending specially crafted OIDC authentication requests to the gateway. The vulnerability resides specifically in the OIDC handshake process; therefore, systems that are not configured to use OpenID Connect for user authentication are not subject to this specific authentication flow flaw.

Why should I care about this vulnerability based on my environment?

According to Halo Surface Signal, this software is inherently designed to be public-facing to facilitate remote work, which significantly increases the risk of internet-based exploitation. If your instance is accessible from the internet, it is a high-priority target because the vulnerability does not require prior authentication to execute.

How should I respond if I am running Claroty Secure Access?

Your first step is to perform an inventory of all deployed instances to identify those using OIDC for authentication. Once mapped, coordinate with your infrastructure or platform teams to verify the version in use. Evaluate the business criticality of these gateways and prepare to apply patches or configuration changes as directed by the vendor.

References