VulnerabilityModified
CVE-2015-4664
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
CRITICAL 9.8EPSS 20.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.58% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- broadcom/privileged access manager · xceedium/xsuite
- Source
- vuln@ca.com
References
- http://packetstormsecurity.com/files/132809/Xceedium-Xsuite-Command-Injection-XSS-Traversal-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.modzero.ch/advisories/MZ-15-02-Xceedium-Xsuite.txtExploit, Third Party Advisory
- https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlVendor Advisory
- https://www.exploit-db.com/exploits/37708/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/132809/Xceedium-Xsuite-Command-Injection-XSS-Traversal-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://www.modzero.ch/advisories/MZ-15-02-Xceedium-Xsuite.txtExploit, Third Party Advisory
- https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlVendor Advisory
- https://www.exploit-db.com/exploits/37708/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.