### [CVE-2018-9022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9022) ![](https://img.shields.io/static/v1?label=Product&message=CA%20Privileged%20Access%20Manager&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Authentication%20Bypass&color=brighgreen) ### Description An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file. ### POC #### Reference - http://packetstormsecurity.com/files/155576/Broadcom-CA-Privileged-Access-Manager-2.8.2-Remote-Command-Execution.html #### Github - https://github.com/ARPSyndicate/cvemon