nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-44092 CVE-2023-44092
HIGH
OS Command Injection
Record summary
CVE-2023-44092 has a selected CVSS score of 7.6 (high).
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Pandora FMSBrowse Pandora FMS / Pandora FMSDefault status: unaffected | CVE List | 700 to ≤ <776 | affected |
pandora_fmsBrowse artica / pandora_fmsDefault status: unknown | CVE List | 700 to < 776 | affected |
References
2pandorafms.comVendor advisory
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures