Authentication Strategy Vulnerability in Broadcom's PAM Products
CVE-2025-24506

5.3MEDIUM

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
30 January 2025

Summary

A flaw in the authentication strategy deployed in Broadcom's PAM products exposes the unique identifiers of users associated with specific authentication types. This could enable unauthorized parties to infer sensitive user associations, thereby compromising user data integrity and privacy. Organizations using affected versions are encouraged to review their configurations and apply relevant security measures to mitigate potential risks.

Affected Version(s)

Symantec Privileged Access Management 3.4.6

Symantec Privileged Access Management 3.4.6

Symantec Privileged Access Management 4.1.0 <= 4.1.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Grönke ([email protected])
.