
CVE-2025-24507
https://notcve.org/view.php?id=CVE-2025-24507
30 Jan 2025 — This vulnerability allows appliance compromise at boot time. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 •

CVE-2025-24506
https://notcve.org/view.php?id=CVE-2025-24506
30 Jan 2025 — A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-203: Observable Discrepancy •

CVE-2025-24505
https://notcve.org/view.php?id=CVE-2025-24505
30 Jan 2025 — This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2025-24504
https://notcve.org/view.php?id=CVE-2025-24504
30 Jan 2025 — An improper input validation the CSRF filter results in unsanitized user input written to the application logs. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-20: Improper Input Validation •

CVE-2025-24503
https://notcve.org/view.php?id=CVE-2025-24503
30 Jan 2025 — A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-384: Session Fixation •

CVE-2025-24502
https://notcve.org/view.php?id=CVE-2025-24502
30 Jan 2025 — An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-384: Session Fixation •

CVE-2025-24501
https://notcve.org/view.php?id=CVE-2025-24501
30 Jan 2025 — An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-20: Improper Input Validation •

CVE-2025-24500
https://notcve.org/view.php?id=CVE-2025-24500
30 Jan 2025 — The vulnerability allows an unauthenticated attacker to access information in PAM database. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-863: Incorrect Authorization •

CVE-2024-38496 – Symantec Privileged Access Manager Insecure Direct Object Reference vulnerability
https://notcve.org/view.php?id=CVE-2024-38496
15 Jul 2024 — The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships. La vulnerabilidad permite que un usuario malicioso de PAM con pocos privilegios acceda a información sobre otros usuarios de PAM y sus membresías grupales. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-922: Insecure Storage of Sensitive Information •

CVE-2024-38495 – Symantec Privileged Access Manager User Enumeration vulnerability
https://notcve.org/view.php?id=CVE-2024-38495
15 Jul 2024 — A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database. Una estrategia de autenticación específica permite a un atacante malintencionado conocer los identificadores de todos los usuarios de PAM definidos en su base de datos. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 •