CVE-2024-38493: Broadcom Symantec Privileged Access Management

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.

Affected products

  • Broadcom Symantec Privileged Access Management: from 4.1.0, up to and including 4.1.7

Published 2024-07-15. Last modified 2026-06-17.