Unauthenticated Admin Account Takeover Via Cron Log File Backups
CVE-2023-4677

7HIGH

Key Information:

Vendor
CVE Published:
23 November 2023

What is CVE-2023-4677?

The vulnerability in Pandora FMS allows attackers to exploit exposed cron log backup files that contain sensitive administrator session IDs. If an attacker gains access to the Pandora FMS Console, they can easily locate and scrape these cron logs. Once they obtain the admin session IDs, they can impersonate administrators and access the application with elevated privileges, posing a serious risk to the security and integrity of the system. It’s crucial for organizations using affected versions of Pandora FMS to implement mitigation strategies to safeguard against potential attacks.

Affected Version(s)

Pandora FMS all 700 <= 772

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oliver Brooks <[email protected]>
.