« Volver al listado

PAM

PAM: vulnerabilidades y CVE

PAM tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-53120Crítica (9.4)9.7%—25 ago 2025
A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on…
CVE-2025-53118Crítica (9.8)31%—25 ago 2025
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the…
CVE-2025-24505Alta (8.8)0.29%—30 ene 2025
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
CVE-2025-24503Crítica (9.3)0.24%—30 ene 2025
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
CVE-2024-38494Alta (8.6)0.61%—15 jul 2024
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
CVE-2005-2977Baja (2.1)0.43%—1 nov 2005
The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.
CVE-2002-1227Alta (7.5)2.4%—28 oct 2002
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.
CVE-1999-0342Media (6.2)0.33%—1 dic 1998
Linux PAM modules allow local users to gain root access using temporary files.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1078 Valid Accounts2
  3. T1190 Exploit Public-Facing Application2
  4. T1203 Exploitation for Client Execution1
  5. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.