CVE-2025-24502: Broadcom Symantec Privileged Access Management
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
Affected products
- Broadcom Symantec Privileged Access Management: version 3.4.6 only; from 4.1.0, up to and including 4.1.8; version 4.2.0 only
Published 2025-01-30. Last modified 2026-06-17.