OS Command Injection Vulnerability Affects Pandora FMS from 700 to 776
CVE-2023-44092

7.6HIGH

Key Information:

Vendor
CVE Published:
19 March 2024

What is CVE-2023-44092?

A vulnerability exists in Pandora FMS due to the improper handling of special elements in OS commands, allowing attackers to perform OS Command Injection. This flaw enables the creation of a reverse shell, facilitating unauthorized command execution within the operating system. The issue is pertinent across multiple versions of Pandora FMS, emphasizing the need for immediate updates to secure affected installations.

Affected Version(s)

Pandora FMS all 700

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aleksey Solovev (Positive Technologies)
.