Improper Session Validation in Broadcom Product
CVE-2025-24502

5.3MEDIUM

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
30 January 2025

Summary

A vulnerability has been identified that allows an unauthenticated attacker to exploit improper session validation within certain Broadcom products. By spoofing the client IP address, the attacker can trigger request notifications as if they were a legitimate user. This could lead to unauthorized actions being executed in the context of an incorrect user, potentially compromising the integrity of the application and the data it handles.

Affected Version(s)

Symantec Privileged Access Management 3.4.6

Symantec Privileged Access Management 3.4.6

Symantec Privileged Access Management 4.1.0 <= 4.1.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Grönke ([email protected])
.