CVE-2020-11847

Published at:
2024-08-21T14:15:07.957

Global infos:

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

CVE Status: Analyzed

References:

  • [email protected]
  • Metrics:

    AttributeValue
    Attack ComplexityLOW
    Attack VectorLOCAL
    Availability ImpactHIGH
    Base Score8.2
    Base SeverityHIGH
    Confidentiality ImpactHIGH
    Integrity ImpactHIGH
    Privileges RequiredLOW
    ScopeCHANGED
    User InteractionREQUIRED
    Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
    Exploitability Score1.5
    Impact Score6
    Source[email protected]
    TypeSecondary

    Links:

    Exploit-db
    Github