Unrestricted access between network segments - Azure AD
Description
Azure Active Directory Graph API services can be accessed and used from anywhere on the Internet. Note: the URL of the service as well as the credentials to use it were found in the application code.
Impact
- Access to confidential information from any computer on the Internet.
- Edit information from any computer on the Internet.
Recommendation
Verify Azure documentation regarding Conditional Access policy and securely configure the service by establishing trusted locations to access the service.
Threat
Authorized user from the Internet.
Expected Remediation Time
⌚ 60 minutes.
Score
Default score using CVSS 3.1. It may change depending on the context of the src.
Base
- Attack vector: N
- Attack complexity: L
- Privileges required: L
- User interaction: N
- Scope: C
- Confidentiality: L
- Integrity: L
- Availability: N
Temporal
- Exploit code maturity: X
- Remediation level: O
- Report confidence: X
Result
- Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:X/RL:O/RC:X
- Score:
- Severity:
- Base: Medium
- Temporal: Medium
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): L
- Integrity (SI): L
- Availability (SA): L
Threat 4.0
Result 4.0
- Vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/E:X
- Score:
- Severity:
Requirements
Fixes
Free trial