VYPR

PAM

by Broadcom Corporation

CVEs (11)

  • CVE-2024-38492CriJul 15, 2024
    risk 0.61cvss epss 0.01

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

  • CVE-2024-36456CriJul 15, 2024
    risk 0.61cvss epss 0.01

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

  • CVE-2025-24503CriJan 30, 2025
    risk 0.60cvss epss 0.00

    A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

  • CVE-2025-24505HigJan 30, 2025
    risk 0.57cvss epss 0.00

    This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.

  • CVE-2022-25625HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.01

    A malicious unauthorized PAM user can access the administration configuration data and change the values.

  • CVE-2024-38494HigJul 15, 2024
    risk 0.56cvss epss 0.01

    This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

  • CVE-2025-24506MedJan 30, 2025
    risk 0.34cvss epss 0.00

    A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.

  • CVE-2025-24501MedJan 30, 2025
    risk 0.34cvss epss 0.00

    An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.

  • CVE-2024-38495MedJul 15, 2024
    risk 0.34cvss epss 0.00

    A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.

  • CVE-2024-36457MedJul 15, 2024
    risk 0.34cvss epss 0.00

    The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

  • CVE-2024-38496MedJul 15, 2024
    risk 0.33cvss epss 0.00

    The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.