Post-Authentication Arbitrary File Read Vulnerability Affects Pandora FMS Plugin Edition Feature
CVE-2024-35308

8.8HIGH

Key Information:

Vendor
CVE Published:
22 October 2024

What is CVE-2024-35308?

The vulnerability located in Pandora FMS relates to the plugin edition feature, specifically in its server plugins section. It allows an unauthorized user to read arbitrary files within the server after authentication. This flaw affects versions of Pandora FMS from 700 up to, but not including, 777.3. The exposure serves as a significant risk, potentially leading to unauthorized access to sensitive information stored on the server.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.