SSH Authenticated Users Can Execute OS Commands for Full System Access
CVE-2020-11847

7.8HIGH

Key Information:

Vendor
Opentext
Vendor
CVE Published:
21 August 2024

Summary

An issue exists within NetIQ's Privileged Access Manager that allows SSH authenticated users to execute arbitrary OS commands on the PAM server. This vulnerability permits full system access through the exploitation of the command execution capability via the shell (bash). Organizations utilizing affected versions of Privileged Access Manager prior to 3.7.0.1 may face significant security risks, including unauthorized access and potential system compromise.

Affected Version(s)

Privileged Access Manager Windows 3.7.0.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.