CVE-2019-13035

HIGH

Pandorafms Pandora Fms < 7.0_ng_735 - Privilege Escalation

Title source: rule
STIX 2.1

Description

Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 27.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
pandorafms/pandora_fms < 7.0_ng_735
Published Jun 29, 2019
Tracked Since Feb 18, 2026