CVE-2024-36458: Symantec Privileged Access Manager Privilege Escalation vulnerability
Published Jul 15, 2024
·Updated
The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.
Affected Software
1 affected component
Symantec Privileged Access Manager
Event History
Jul 15, 2024
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36458?
CVE-2024-36458 is considered a moderate severity vulnerability due to its potential impact on server security.
2
How do I fix CVE-2024-36458?
To fix CVE-2024-36458, ensure that you apply the latest security patches provided by Symantec for the Privileged Access Manager.
3
Who is affected by CVE-2024-36458?
Low-privileged PAM users in systems utilizing Symantec Privileged Access Manager are affected by CVE-2024-36458.
4
What actions can be performed due to CVE-2024-36458?
CVE-2024-36458 allows a low-privileged PAM user to perform server upgrade related actions without appropriate permissions.
5
Is user authentication affected by CVE-2024-36458?
CVE-2024-36458 does not directly impact user authentication but may allow unauthorized actions that compromise server integrity.