CRITICAL🇵🇱 Wersja polska

CVE-2024-36455

CVSS 9.4v4.0pub. 2024-07-15upd. 2026-04-15

An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

🤖 AI Analysis
How it works

The vulnerability results from improper input validation (CWE-665 — improper initialization/validation) in the component handling HTTP requests of the PAM system. An attacker located in the local network (attack vector AV:A) can send a specially crafted HTTP request without needing to possess any credentials. This request bypasses authentication mechanisms and leads to execution of arbitrary commands at the operating system level of the PAM device.

Impact

An attacker can gain full control over the PAM system, including executing arbitrary commands on the server, which in the case of a privileged access management system can lead to compromise of the entire IT infrastructure — takeover of privileged accounts, access to critical systems, and lateral movement in the network.

Mitigation & patch

Apply patches available from the vendor in accordance with references published by Broadcom at: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678. Until updates are applied, it is recommended to restrict access to the PAM system's HTTP interface exclusively to trusted network segments (firewall, network segmentation).

Who is affected

Broadcom PAM (Privileged Access Management) systems — specific versions indicated in the vendor references (Broadcom advisory no. 24678)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References