PT-2022-17776 · Unknown · Pandora Fms

Published

2022-08-01

·

Updated

2022-08-05

·

CVE-2022-26308

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 7.0NG.760 and below
Description The issue allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
Recommendations For Pandora FMS versions 7.0NG.760 and below, consider restricting the role of Operator (Write) to prevent unauthorized access to the Credential store until a patch is available. As a temporary workaround, limit the permissions of users with the Operator (Write) role to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-26308

Affected Products

Pandora Fms