Bypass Vulnerability in Imprivata Enterprise Access Management for Windows Systems
CVE-2024-12310

7HIGH

Key Information:

Vendor

Imprivata

Vendor
CVE Published:
23 July 2025

What is CVE-2024-12310?

A vulnerability in Imprivata Enterprise Access Management allows unauthorized users to bypass the login screen of shared kiosk workstations. This is possible due to insufficient handling of keyboard shortcuts, enabling access to the underlying Windows system through an already logged-in autologon account. This issue impacts various versions of the product, leaving systems exposed to potential security breaches.

Affected Version(s)

Enterprise Access Management 5.3 <= 24.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Patrik von Allmen (Redguard AG)
.