Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2024-38494
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2024-38493
Disclosure Date: July 15, 2024 (last updated September 11, 2024)
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
0
Attacker Value
Unknown
CVE-2024-38492
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown
CVE-2024-38491
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
0
Attacker Value
Unknown
CVE-2024-36458
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
0
Attacker Value
Unknown
CVE-2024-36457
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
0
Attacker Value
Unknown
CVE-2024-36456
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown
CVE-2024-36455
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2022-25625
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A malicious unauthorized PAM user can access the administration configuration data and change the values.
0