CVE-2025-24505

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Feb 2025, 06:15

Type Values Removed Values Added
References
  • {'url': 'https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678', 'source': 'secure@symantec.com'}
  • () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25362 -
Summary
  • (es) Esta vulnerabilidad permite que un usuario PAM autenticado con altos privilegios logre la ejecución remota de comandos en el PAM afectado sistema cargando un archivo de actualización manipulado especial.

30 Jan 2025, 20:15

Type Values Removed Values Added
CWE CWE-434

30 Jan 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 19:15

Updated : 2025-02-05 06:15


NVD link : CVE-2025-24505

Mitre link : CVE-2025-24505

CVE.ORG link : CVE-2025-24505


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type