PT-2024-4343 · Unknown · Pandora Fms

Aleksey Solovev

·

Published

2024-06-10

·

Updated

2024-06-10

·

CVE-2024-35306

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandora FMS versions 700 through 776
Description The issue is related to OS Command injection in Ajax PHP files via HTTP Request, allowing the execution of system commands by exploiting variables. This can enable an attacker to execute arbitrary commands in the files.
Recommendations For Pandora FMS versions 700 through 776, consider disabling the execution of system commands in Ajax PHP files until a patch is available. Restrict access to the vulnerable Ajax PHP files to minimize the risk of exploitation. Avoid using variables that can be exploited via HTTP requests in the affected files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04832
CVE-2024-35306

Affected Products

Pandora Fms