PT-2023-8542 · Unknown · Pandora Fms
Published
2023-11-21
·
Updated
2025-01-16
·
CVE-2023-4677
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions <= 772
Description
The issue is related to insufficient protection of registration data in the Pandora FMS Console, allowing an attacker to gain unauthorized access to protected information and elevate their privileges to the administrator level. An attacker can scrape the cron logs directory for cron log backups, which contain administrator session IDs, and abuse the contents to authenticate to the application as an administrator.
Recommendations
For versions <= 772, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the cron logs directory to minimize the risk of exploitation. Avoid using the administrator session IDs in the cron log backups until the issue is resolved.
Fix
Improper Authentication
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pandora Fms