PT-2025-5374 · Broadcom · Symantec Privileged Access Management

Stefan Grönke

·

Published

2025-01-30

·

Updated

2025-02-05

·

CVE-2025-24502

CVSS v4.0

5.3

Medium

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2025-24502

Affected Products

Symantec Privileged Access Management