A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.
CVE ID: CVE-2024-10963
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 15.73% (scored less or equal to compared to others)
EPSS Date: 2025-03-07 (when was this score calculated)