CVE-2023-4677

HIGH

Artica Pandora Fms < 773 - Authentication Bypass

Title source: rule
STIX 2.1

Description

Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.

References (1)

Core 1
Core References

Scores

CVSS v3 7.0
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-532
Status published
Products (1)
artica/pandora_fms 700 - 773
Published Nov 23, 2023
Tracked Since Feb 18, 2026