QID 91928
Date Published: 2022-08-08
QID 91928: Okta Advanced Server Access Client (ScaleFT) Windows Remote Code Execution (RCE) Vulnerability
Okta Advanced Server Access (ScaleFT) is a tool allowing organizations to secure access to SSH and RDP servers via a centralized authentication method.
Affected Versions:
Okta Advanced Server Access Client for Windows prior to version 1.57.0.
QID Detection Logic (Authenticated):
This QID checks for the vulnerable file version of ScaleFT.exe and determines whether the host vulnerable.
Vulnerable versions of Okta Advanced Server Access Client for Windows are found to be vulnerable to command injection via a specially crafted URL.
Solution
The vendor has released updates to resolve this issue.
Customers are advised to visit Okta Advanced Server Access Client for latest version and more information on this vulnerability.
Vendor References
- Okta Advanced Server Access Client -
trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295/
CVEs related to QID 91928
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Okta Advanced Server Access Client |
|