PAM
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38492 | Cri | 0.61 | — | 0.01 | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file. | ||
| CVE-2024-36456 | Cri | 0.61 | — | 0.01 | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file. | ||
| CVE-2025-24503 | Cri | 0.60 | — | 0.00 | Jan 30, 2025 | A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. | ||
| CVE-2025-24505 | Hig | 0.57 | — | 0.00 | Jan 30, 2025 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file. | ||
| CVE-2022-25625 | Hig | 0.57 | 8.8 | 0.01 | Aug 26, 2022 | A malicious unauthorized PAM user can access the administration configuration data and change the values. | ||
| CVE-2024-38494 | Hig | 0.56 | — | 0.01 | Jul 15, 2024 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request. | ||
| CVE-2025-24506 | Med | 0.34 | — | 0.00 | Jan 30, 2025 | A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types. | ||
| CVE-2025-24501 | Med | 0.34 | — | 0.00 | Jan 30, 2025 | An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request. | ||
| CVE-2024-38495 | Med | 0.34 | — | 0.00 | Jul 15, 2024 | A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database. | ||
| CVE-2024-36457 | Med | 0.34 | — | 0.00 | Jul 15, 2024 | The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint. | ||
| CVE-2024-38496 | Med | 0.33 | — | 0.00 | Jul 15, 2024 | The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships. |
- risk 0.61cvss —epss 0.01
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
- risk 0.61cvss —epss 0.01
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
- risk 0.60cvss —epss 0.00
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
- risk 0.57cvss —epss 0.00
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
- risk 0.57cvss 8.8epss 0.01
A malicious unauthorized PAM user can access the administration configuration data and change the values.
- risk 0.56cvss —epss 0.01
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
- risk 0.34cvss —epss 0.00
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
- risk 0.34cvss —epss 0.00
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
- risk 0.34cvss —epss 0.00
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
- risk 0.34cvss —epss 0.00
The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
- risk 0.33cvss —epss 0.00
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.