CVE-2024-3094 impact on PAM
search cancel

CVE-2024-3094 impact on PAM

book

Article ID: 281458

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Is the PAM Physical appliance build affected by this vulnerability CVE-2024-3094 - XZ Backdoor. Please provide confirmation if and how this affects Broadcom PAM appliance build.

Resolution

PAM 4.1.X releases run on a customized Debian 9 release with xz-utils version 5.2.2-1.2+b1. This version is not affected. The vulnerability was introduced in 2023 in the 5.6 and 5.6.1 releases and affects unstable Debian Linux releases only, see https://security-tracker.debian.org/tracker/CVE-2024-3094.