CVE-2024-10963
published 2024-11-07CVE-2024-10963: A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick…
PriorityP346high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.79%
52.5th percentile
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.7.0-5 (forky) | pam 1.7.0-5 (forky) |
| msrc | azl3_pam_1.5.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_pam_1.5.3-4_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_pam_1.5.1-7_on_cbl_mariner_2.0 | — | — |
| pam | pam | >= 0 < 1.7.0-5 | 1.7.0-5 |
| pam | pam | >= 0 < 1.7.0-5 | 1.7.0-5 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4LOW
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM vulnerability
vendor_ubuntu·2025-09-22
CVE-2024-10963 PAM vulnerability
Title: PAM vulnerability
Summary: PAM could allow unintended access to network services.
It was discovered that the PAM pam_access module incorrectly parsed
certain rules as hostnames. An attacker could possibly use this issue to
spoof hostnames and bypass access restrictions.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Microsoft
Pam: improper hostname interpretation in pam_access leads to access control bypass
vendor_msrc·2024-11-12·CVSS 7.4
CVE-2024-10963 [HIGH] CWE-287 Pam: improper hostname interpretation in pam_access leads to access control bypass
Pam: improper hostname interpretation in pam_access leads to access control bypass
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Relea
Red Hat
pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass
vendor_redhat·2024-11-07·CVSS 7.4
CVE-2024-10963 [HIGH] CWE-287 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass
pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminal
Debian
CVE-2024-10963: pam - A flaw was found in pam_access, where certain rules in its configuration file ar...
vendor_debian·2024·CVSS 7.4
CVE-2024-10963 [HIGH] CVE-2024-10963: pam - A flaw was found in pam_access, where certain rules in its configuration file ar...
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.7.0-5)
sid: resolved (fixed in 1.7.0-5)
trixie: resolved (fixed in 1.7.0-5)
OSV
CVE-2024-10963: A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames
osv·2024-11-07·CVSS 7.4
CVE-2024-10963 [HIGH] CVE-2024-10963: A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
GHSA
GHSA-rw99-6hrh-fmjr: A vulnerability was found in pam_access due to the improper handling of tokens in access
ghsa_unreviewed·2024-11-07
CVE-2024-10963 [MEDIUM] CWE-287 GHSA-rw99-6hrh-fmjr: A vulnerability was found in pam_access due to the improper handling of tokens in access
A vulnerability was found in pam_access due to the improper handling of tokens in access.conf, interpreted as hostnames. This flaw allows attackers to bypass access restrictions by spoofing hostnames, undermining configurations designed to limit access to specific TTYs or services. The flaw poses a risk in environments relying on these configurations for local access control.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:10232https://access.redhat.com/errata/RHSA-2024:10244https://access.redhat.com/errata/RHSA-2024:10379https://access.redhat.com/errata/RHSA-2024:10518https://access.redhat.com/errata/RHSA-2024:10528https://access.redhat.com/errata/RHSA-2024:10852https://access.redhat.com/security/cve/CVE-2024-10963https://bugzilla.redhat.com/show_bug.cgi?id=2324291https://github.com/linux-pam/linux-pam/issues/834https://github.com/linux-pam/linux-pam/pull/835
2024-11-07
Published