Record summary

CVE-2020-8497 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 8, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMArtica Pandora FMS <=7.42 - Arbitrary File ReadCVSS 5.3

Artica Pandora FMS through 7.42 is susceptible to arbitrary file read. An attacker can read the chat history, which is in JSON format and contains user names, user IDs, private messages, and timestamps. This can potentially lead to unauthorized data modification and other operations.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to sensitive information, potentially leading to further compromise of the system.

Remediation

Upgrade Artica Pandora FMS to version 7.43 or later to mitigate this vulnerability.

WeaknessesCWE-306
Authorsgy741
Template tagscvecve2020fmsarticavulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*
Shodan: http.title:"pandora fms"
FOFA: title="pandora fms"
Google: intitle:"pandora fms"

Source: ProjectDiscovery

References

2