CVE-2024-25649: Delinea Secret Server

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

Affected products

  • Delinea Secret Server: version 11.4.000000 only

Published 2024-03-14. Last modified 2026-06-17.