CVE-2024-38494
- EPSS 0.41%
- Veröffentlicht 15.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:05
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
CVE-2024-38493
- EPSS 0.07%
- Veröffentlicht 15.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:05
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side co...
CVE-2024-38492
- EPSS 1.16%
- Veröffentlicht 15.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:05
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
CVE-2024-38491
- EPSS 0.07%
- Veröffentlicht 15.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:05
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
CVE-2024-36458
- EPSS 0.05%
- Veröffentlicht 15.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 21:15:20
The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
CVE-2024-36457
- EPSS 0.02%
- Veröffentlicht 15.07.2024 14:15:02
- Zuletzt bearbeitet 21.11.2024 09:22:13
The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
CVE-2024-36456
- EPSS 0.97%
- Veröffentlicht 15.07.2024 14:15:02
- Zuletzt bearbeitet 21.11.2024 09:22:13
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
CVE-2024-36455
- EPSS 0.83%
- Veröffentlicht 15.07.2024 14:15:02
- Zuletzt bearbeitet 21.11.2024 09:22:13
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
CVE-2022-25625
- EPSS 0.32%
- Veröffentlicht 26.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:52:28
A malicious unauthorized PAM user can access the administration configuration data and change the values.