peter bassill · operator
$ cve CVE-2018-9021 JSON

CVE-2018-9021 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 9.6% (pctl 95)

Patch early

A public exploit exists.

Description

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.61% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploityes
Published2018-06-18
Last modified2026-06-17

Affected (1)

VendorProduct
broadcomprivileged access manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD