PT-2022-17776 · Unknown · Pandora Fms
Published
2022-08-01
·
Updated
2022-08-05
·
CVE-2022-26308
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions 7.0NG.760 and below
Description
The issue allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
Recommendations
For Pandora FMS versions 7.0NG.760 and below, consider restricting the role of Operator (Write) to prevent unauthorized access to the Credential store until a patch is available.
As a temporary workaround, limit the permissions of users with the Operator (Write) role to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms