PT-2023-8542 · Unknown · Pandora Fms

CVE-2023-4677

·

Publicado

2023-11-21

·

Atualizado

2025-01-16

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pandora FMS versions <= 772
Description The issue is related to insufficient protection of registration data in the Pandora FMS Console, allowing an attacker to gain unauthorized access to protected information and elevate their privileges to the administrator level. An attacker can scrape the cron logs directory for cron log backups, which contain administrator session IDs, and abuse the contents to authenticate to the application as an administrator.
Recommendations For versions <= 772, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the cron logs directory to minimize the risk of exploitation. Avoid using the administrator session IDs in the cron log backups until the issue is resolved.

Correção

Improper Authentication

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01145
CVE-2023-4677

Produtos afetados

Pandora Fms