CVE-2023-4677
Last modified
CVE-2023-4677 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Artica | Pandora Fms | >= 700, < 773 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4677?
How severe is CVE-2023-4677?
How do I fix CVE-2023-4677?
Are you affected by CVE-2023-4677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
