CVE-2024-36455

CWE-6653 documents3 sources
Severity
9.4CRITICAL
EPSS
1.1%
top 21.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15

Description

An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Packages1 packages

CVEListV5broadcom/symantec_privileged_access_management3.4.6, 4.1.0 - 4.1.7+1

🔴Vulnerability Details

2
CVEList
Symantec Privileged Access Manager Remote Command Execution vulnerability2024-07-15
GHSA
GHSA-g5x7-p429-mq3p: An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially2024-07-15
CVE-2024-36455 (CRITICAL CVSS 9.4) | An improper input validation allows | cvebase.io