{"id":"CVE-2024-10963","title":"A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames","summary":"A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized acces…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-287"],"published":"2024-11-07","updated":"2026-08-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-10963","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:10232","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10244","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10379","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10518","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10528","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10852","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6122","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-10963","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2324291","label":"secalert@redhat.com"},{"url":"https://github.com/linux-pam/linux-pam/issues/834","label":"secalert@redhat.com"},{"url":"https://github.com/linux-pam/linux-pam/pull/835","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00781,"epssPercentile":0.54505,"ingestedAt":"2026-08-11T16:47:03.399Z","slug":"CVE-2024-10963","body":"## Overview\n\nA flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}