Unauthenticated Admin Account Takeover Via Cron Log File Backups
CVE-2023-4677
What is CVE-2023-4677?
The vulnerability in Pandora FMS allows attackers to exploit exposed cron log backup files that contain sensitive administrator session IDs. If an attacker gains access to the Pandora FMS Console, they can easily locate and scrape these cron logs. Once they obtain the admin session IDs, they can impersonate administrators and access the application with elevated privileges, posing a serious risk to the security and integrity of the system. It’s crucial for organizations using affected versions of Pandora FMS to implement mitigation strategies to safeguard against potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pandora FMS all 700 <= 772
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
