Path Traversal Vulnerability Affects Pandora FMS from 700 to 776
CVE-2023-41793

6.7MEDIUM

Key Information:

Vendor
CVE Published:
19 March 2024

What is CVE-2023-41793?

A Path Traversal vulnerability exists in Pandora FMS versions 700 through 775, allowing attackers to navigate the file system beyond the intended directories. This security issue enables unauthorized changing of directories, as well as the potential to create and download files outside the permitted pathways. Exploitation of this vulnerability could lead to unauthorized access to sensitive files and data, posing significant risks to system integrity and confidentiality.

Affected Version(s)

Pandora FMS all 700

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aleksey Solovev (Positive Technologies)
.