AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-9191

HIGH · CVSS 7.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-11-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It affects Windows.

CVE
CVE-2024-9191
Severity
HIGH
CVSS
7.1
EPSS
0.24%
Windows

Original NVD Description

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing. Note: A precondition of this vulnerability is that the user must be using the Okta Device Access passwordless feature. Okta Device Access users not using passwordless are not affected, and customers only using Okta Verify on platforms other than Windows, or only using FastPass are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)