CVE-2021-32098
CRITICALArtica Pandora FMS 742 - Unauthenticated Remote Code Execution via Phar Deserialization
Title source: llmDescription
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explained
Release Notes, Vendor Advisory x_refsource_misc
https://pandorafms.com/blog/whats-new-in-pandora-fms-743/
Exploit, Third Party Advisory x_refsource_misc
https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack
Scores
CVSS v3
9.8
EPSS
0.0247
EPSS Percentile
82.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
artica/pandora_fms
742
Published
May 07, 2021
Tracked Since
Feb 18, 2026