Symantec Privileged Access Management

Vendor:

First CVE: Aug 26, 2022 · Active for 3 years

10
Total CVEs
More Total CVEs than 89% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Symantec Privileged Access Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2022
3 years ago
Most Recent CVE
Jan 30, 2025
544 days ago

CVE Severity & Scoring

Symantec Privileged Access Management10 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network2 (20.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None8 (80.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A malicious unauthorized PAM user can access the administration configuration data and change the values.
Aug 26, 20228.828NONO
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.
Jan 30, 20259.327NONO
This vulnerability allows appliance compromise at boot time.
Jan 30, 20258.924NONO
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
Jan 30, 20258.824NONO
The vulnerability allows an unauthenticated attacker to access information in PAM database.
Jan 30, 20258.723NONO
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the P
Jul 15, 20246.118NONO
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
Jan 30, 20255.316NONO
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
Jan 30, 20255.316NONO
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client I
Jan 30, 20255.316NONO
An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
Jan 30, 20255.316NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Symantec Privileged Access Management

Top CWEs

Versions

No cataloged versions.