CVE-2024-38494: Symantec Privileged Access Manager Remote Command Execution vulnerability
Published Jul 15, 2024
·Updated
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
Affected Software
1 affected component
Symantec Privileged Access Manager
Event History
Jul 15, 2024
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38494?
CVE-2024-38494 is rated as a critical severity vulnerability due to its potential for remote command execution by high-privileged authenticated users.
2
How do I fix CVE-2024-38494?
To remediate CVE-2024-38494, apply the latest security patches provided by Symantec for the Privileged Access Manager.
3
Who is affected by CVE-2024-38494?
CVE-2024-38494 affects users of Symantec Privileged Access Manager that have high-privileged account access.
4
What type of attack does CVE-2024-38494 enable?
CVE-2024-38494 enables attackers to execute arbitrary commands remotely on the affected PAM system.
5
When was CVE-2024-38494 disclosed?
CVE-2024-38494 was disclosed in 2024 and is currently under active remediation by affected parties.