PT-2024-6647 · Su+4 · Su+4

3V1N0

+3

·

Published

2024-10-03

·

Updated

2025-08-26

·

CVE-2024-9313

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Authd PAM module versions prior to 0.3.5
Description: The issue is related to errors in privilege management, allowing a remote attacker to gain access to another user's account by executing commands such as su, sudo, or ssh and modifying their transactions. This can enable broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.
Recommendations: For Authd PAM module versions prior to 0.3.5, update to version 0.3.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of su, sudo, and ssh commands to minimize the risk of exploitation. Additionally, ensure that tools such as su, sudo, and ssh are updated to versions that include the necessary fixes, such as su version that will include https://github.com/util-linux/util-linux/pull/3206, ssh version that will include https://github.com/openssh/openssh-portable/pull/521, and sudo version that will include https://github.com/sudo-project/sudo/pull/412.

Fix

Improper Privilege Management

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-07815
CVE-2024-9313
GHSA-X5Q3-C8RM-W787
GO-2024-3181
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2024:3911-1
SUSE-SU-2025:0429-1

Affected Products

Authd Pam Module
Suse
Ssh
Su
Sudo