PT-2023-8737 · Unknown · Pandora Fms

Published

2023-11-23

·

Updated

2024-01-09

·

CVE-2023-41786

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 700 through 772
Description The issue is related to the exposure of sensitive information to unauthorized actors, allowing users with low privileges to download database backups. This can be exploited by a remote attacker to gain access to sensitive data. The vulnerability is associated with a lack of protection for service data.
Recommendations For versions 700 through 772, update to a version that includes a fix for this issue to prevent unauthorized access to database backups. As a temporary workaround, consider restricting access to the database backup functionality to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-01769
CVE-2023-41786

Affected Products

Pandora Fms