CVE-2024-38494

Severity
8.6HIGH
EPSS
0.6%
top 31.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15

Description

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Packages1 packages

CVEListV5broadcom/symantec_privileged_access_management3.4.6, 4.1.0 - 4.1.7+1

🔴Vulnerability Details

2
CVEList
Symantec Privileged Access Manager Remote Command Execution vulnerability2024-07-15
GHSA
GHSA-m9f2-w9fv-j46g: This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a special2024-07-15
CVE-2024-38494 (HIGH CVSS 8.6) | This vulnerability allows a high-pr | cvebase.io