Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:LDefault status
unaffected
< 24.3.0 HF4, and < 21.0.13 HF1 (custom)
affected
24.3.0 HF4 or later, and 21.0.13 HF1 or later (custom)
unaffected
Description
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
Problem types
Product status
< 24.3.0 HF4, and < 21.0.13 HF1 (custom)
24.3.0 HF4 or later, and 21.0.13 HF1 or later (custom)
Credits
Flora Schäfer, secuvera GmbH
References
support.broadcom.com/...l/content/SecurityAdvisories/0/25732
www.secuvera.de/advisories/secuvera-SA-2025-01.txt