Symantec Privileged Access Management
19 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Symantec Privileged Access Management, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Symantec Privileged Access Management CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 8 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium1
Latest CVEs
The 15 most recently published vulnerabilities affecting Symantec Privileged Access Management.
- CVE-2025-24507This vulnerability allows appliance compromise at boot time.—
- CVE-2025-24506A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.—
- CVE-2025-24505This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.—
- CVE-2025-24504An improper input validation the CSRF filter results in unsanitized user input written to the application logs.—
- CVE-2025-24503A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.9.6
- CVE-2025-24502An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.—
- CVE-2025-24501An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.—
- CVE-2025-24500The vulnerability allows an unauthenticated attacker to access information in PAM database.—
- CVE-2024-38496Symantec Privileged Access Manager Insecure Direct Object Reference vulnerability—
- CVE-2024-38495Symantec Privileged Access Manager User Enumeration vulnerability—
- CVE-2024-38494Symantec Privileged Access Manager Remote Command Execution vulnerability—
- CVE-2024-38493Symantec Privileged Access Manager Reflected Cross Site Scripting vulnerability6.1
- CVE-2024-38492Symantec Privileged Access Manager Remote Command Execution vulnerability—
- CVE-2024-38491Symantec Privileged Access Manager SQL Injection vulnerability—
- CVE-2024-36458Symantec Privileged Access Manager Privilege Escalation vulnerability—
Product grouping is registry-driven, with AI assist and human review. How it works