PAM
PAM: vulnerabilidades y CVE
PAM tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-53120 | Crítica (9.4) | 9.7% | — | 25 ago 2025 | A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on… |
| CVE-2025-53118 | Crítica (9.8) | 31% | — | 25 ago 2025 | An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the… |
| CVE-2025-24505 | Alta (8.8) | 0.29% | — | 30 ene 2025 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file. |
| CVE-2025-24503 | Crítica (9.3) | 0.24% | — | 30 ene 2025 | A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server. |
| CVE-2024-38494 | Alta (8.6) | 0.61% | — | 15 jul 2024 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request. |
| CVE-2005-2977 | Baja (2.1) | 0.43% | — | 1 nov 2005 | The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses. |
| CVE-2002-1227 | Alta (7.5) | 2.4% | — | 28 oct 2002 | PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users. |
| CVE-1999-0342 | Media (6.2) | 0.33% | — | 1 dic 1998 | Linux PAM modules allow local users to gain root access using temporary files. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.