artica Vulnerabilities and Affected Products
Vulnerabilities associated with pandora_fms.
Products
Clear product- pandora_fms4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-35305HIGH | Unauth Time-Based SQL Injection via APIUnauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777. CWE-89Jun 10, 2024 | CVSS8.9v4.0 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44092HIGH | OS Command InjectionImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776. CWE-78Mar 19, 2024 | CVSS7.6v3.1 | EPSS0.846% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-8497MEDIUM | artica pandora_fms Missing Authentication for Critical FunctionIn Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps. | CVSS5.3v3.1 | EPSS5.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-11222HIGH | artica pandora_fms Improper Input ValidationLocal File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint. | CVSS7.5v3.0 | EPSS6.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |