PT-2024-10766 · Unknown · Ca Privileged Access Manager

Published

2024-08-21

·

Updated

2024-08-25

·

CVE-2020-11847

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Privileged Access Manager versions prior to 3.7.0.1
Description The issue allows an SSH authenticated user to execute an OS command and gain full system access using bash when accessing the PAM server.
Recommendations For versions prior to 3.7.0.1, update to version 3.7.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the PAM server or limiting the privileges of SSH authenticated users until a patch is applied.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-11847

Affected Products

Ca Privileged Access Manager