Improper Session Validation in Broadcom Product
CVE-2025-24502
Key Information:
- Vendor
Broadcom
- Vendor
- CVE Published:
- 30 January 2025
What is CVE-2025-24502?
A vulnerability has been identified that allows an unauthenticated attacker to exploit improper session validation within certain Broadcom products. By spoofing the client IP address, the attacker can trigger request notifications as if they were a legitimate user. This could lead to unauthorized actions being executed in the context of an incorrect user, potentially compromising the integrity of the application and the data it handles.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Symantec Privileged Access Management 3.4.6
Symantec Privileged Access Management 3.4.6
Symantec Privileged Access Management 4.1.0 <= 4.1.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved