CVE-2025-24507
- EPSS 0.03%
- Published 30.01.2025 19:15:17
- Last modified 05.02.2025 06:15:31
This vulnerability allows appliance compromise at boot time.
CVE-2025-24506
- EPSS 0.06%
- Published 30.01.2025 19:15:17
- Last modified 05.02.2025 06:15:31
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
CVE-2025-24505
- EPSS 0.05%
- Published 30.01.2025 19:15:17
- Last modified 05.02.2025 06:15:31
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
CVE-2025-24504
- EPSS 0.08%
- Published 30.01.2025 19:15:16
- Last modified 05.02.2025 05:15:11
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
CVE-2025-24503
- EPSS 0.05%
- Published 30.01.2025 19:15:16
- Last modified 05.02.2025 05:15:11
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
CVE-2025-24502
- EPSS 0.06%
- Published 30.01.2025 19:15:14
- Last modified 05.02.2025 05:15:11
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
CVE-2025-24501
- EPSS 0.14%
- Published 30.01.2025 19:15:14
- Last modified 05.02.2025 05:15:11
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
CVE-2025-24500
- EPSS 0.08%
- Published 30.01.2025 19:15:14
- Last modified 13.03.2025 14:15:35
The vulnerability allows an unauthenticated attacker to access information in PAM database.
CVE-2024-38495
- EPSS 0.05%
- Published 15.07.2024 15:15:10
- Last modified 21.11.2024 09:26:05
A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.
CVE-2024-38496
- EPSS 0.05%
- Published 15.07.2024 15:15:10
- Last modified 03.12.2024 19:15:09
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.