PT-2024-28032 · Pam · Pam

Paolo Cavaglià

·

Published

2024-07-15

·

Updated

2024-08-01

·

CVE-2024-38492

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions PAM system (affected versions not specified)
Description The issue allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-38492

Affected Products

Pam