CVE-2024-27312

EUVD-2024-24528
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. 
Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_pam360
𝑥
< 6.6
zohocorpmanageengine_pam360
6.6:build6600
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
manageenginepam360
660q ≤
𝑥
< 6601
ADP