An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
The vulnerability results from improper input validation (CWE-665 — improper initialization/validation) in the component handling HTTP requests of the PAM system. An attacker located in the local network (attack vector AV:A) can send a specially crafted HTTP request without needing to possess any credentials. This request bypasses authentication mechanisms and leads to execution of arbitrary commands at the operating system level of the PAM device.
An attacker can gain full control over the PAM system, including executing arbitrary commands on the server, which in the case of a privileged access management system can lead to compromise of the entire IT infrastructure — takeover of privileged accounts, access to critical systems, and lateral movement in the network.
Apply patches available from the vendor in accordance with references published by Broadcom at: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24678. Until updates are applied, it is recommended to restrict access to the PAM system's HTTP interface exclusively to trusted network segments (firewall, network segmentation).
Broadcom PAM (Privileged Access Management) systems — specific versions indicated in the vendor references (Broadcom advisory no. 24678)
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X