VYPR
Unrated severityNVD Advisory· Published Aug 21, 2024· Updated Aug 22, 2024

Vulnerability in sshrelay in privileged access manager provides full system access.

CVE-2020-11847

Description

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated SSH users can execute arbitrary OS commands on NetIQ Privileged Access Manager before 3.7.0.1, leading to full system compromise.

Vulnerability

CVE-2020-11847 is a command injection vulnerability in NetIQ Privileged Access Manager (PAM). An authenticated SSH user can execute arbitrary OS commands using bash when accessing the PAM server. This affects all versions of Privileged Access Manager before 3.7.0.1 (Patch Update 1). The exact component is not specified in the available reference, but the vulnerability allows command execution via the SSH session [1].

Exploitation

An attacker must have valid SSH credentials to authenticate to the PAM server. Once authenticated, the attacker can execute arbitrary OS commands by leveraging the bash shell. The reference does not provide specific exploitation steps, but the attack vector involves sending crafted input during the SSH session to trigger command execution [1].

Impact

Successful exploitation grants the attacker full system access with the privileges of the PAM server process. This can lead to complete compromise of the affected system, including data exfiltration, installation of backdoors, and lateral movement within the network. The impact is severe due to the high privileges obtained [1].

Mitigation

The vulnerability is fixed in Privileged Access Manager version 3.7.0.1 (Patch Update 1), released in June 2020. Users should upgrade to this version or later. No workarounds are documented in the available reference. The CVE is not listed on the CISA Known Exploited Vulnerabilities catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.