PAM TACPLUS is a focused authentication module that provides TACACS+ protocol support for pluggable authentication mechanisms in Unix and Linux systems, where it manages privileged access and remote authentication at the system level. Observed weakness classes in this project center on information-disclosure and randomness issues, including sensitive data logging, cryptographic entropy gaps, and placeholder categorizations, reflecting the protocol-handling and credential-management demands of an authentication layer. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pam Tacplus Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-20014CRITICAL In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure. | Apr 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-27743CRITICAL libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id. | Oct 26, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-13881HIGH In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. | Jun 6, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pam Tacplus Project.
Media articles that mention a CVE ID that affects a product developed by Pam Tacplus Project — matched by CVE ID, not by vendor name.