PT-2020-13735 · Artica · Artica Pandora Fms
Published
2020-06-11
·
Updated
2020-06-11
·
CVE-2020-13855
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Artica Pandora FMS version 7.44
Description
The issue allows for arbitrary file upload, which can lead to remote command execution. This is possible via the File Repository Manager feature.
Recommendations
For Artica Pandora FMS version 7.44, consider disabling the File Repository Manager feature until a patch is available to prevent arbitrary file uploads and potential remote command execution.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artica Pandora Fms