CVE-2024-38492
Severity CVSS v4.0:
CRITICAL
Type:
CWE-77
Command Injection
Publication date:
15/07/2024
Last modified:
15/04/2026
Description
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



