Broadcom Symantec Security Updates – 30 August 2022

Broadcom Symantec has released security updates to address a new vulnerability. The remote attacker could exploit this vulnerability to take control of the affected system and gain elevated privileges.

The addressed vulnerability could allow the attacker to gain access to affected PAM
configuration endpoints with reading and writing permissions when multi-factor authentication (MFA) is enabled.

Privileged Access Management (PAM) privilege escalation (CVE-2022-25625):

  •  CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

Affected Versions:

  • Broadcom Symantec Privileged Access Management ( 3.4.0 – 3.4.6 ) ( 4.0.0 – 4.0.3 ) and ( 4.1.0 ).

 

Vulnerabilities
  • CVE-2022-25625
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Broadcom Security Advisor

References