9 results (0.044 seconds)

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — This vulnerability allows appliance compromise at boot time. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-203: Observable Discrepancy •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

30 Jan 2025 — This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — An improper input validation the CSRF filter results in unsanitized user input written to the application logs. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-384: Session Fixation •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-384: Session Fixation •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-20: Improper Input Validation •

CVSS: 8.7EPSS: 0%CPEs: 3EXPL: 0

30 Jan 2025 — The vulnerability allows an unauthenticated attacker to access information in PAM database. • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678 • CWE-863: Incorrect Authorization •

CVSS: 9.0EPSS: 0%CPEs: 6EXPL: 0

26 Aug 2022 — A malicious unauthorized PAM user can access the administration configuration data and change the values. Un usuario PAM malicioso y no autorizado puede acceder a los datos de configuración de la administración y cambiar los valores. • https://support.broadcom.com/external/content/SecurityAdvisories/0/20850 •