PT-2022-17779 · Unknown · Pandora Fms

Published

2022-08-01

·

Updated

2022-08-05

·

CVE-2022-26310

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 7.0NG.760 and below
Description The issue allows an improper authorization in User Management, where any authenticated user with access to the User Management module could create, modify, or delete any user with full admin privilege. This could lead to a vertical privilege escalation, allowing access to the privileges of a higher-level user or typically an admin user.
Recommendations For Pandora FMS versions 7.0NG.760 and below, consider restricting access to the User Management module to prevent unauthorized modifications to user privileges until a fix is available. As a temporary workaround, limit the capabilities of users with access to the User Management module to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-26310

Affected Products

Pandora Fms