Description
There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.
No analysis available yet.
Remediation
Vendor Solution
Fixed in v766
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-46946 | There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check. |
References
History
Thu, 27 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-27T20:23:30.280Z
Reserved: 2022-10-28T00:00:00.000Z
Link: CVE-2022-43978
Updated: 2024-08-03T13:47:04.552Z
Status : Modified
Published: 2023-01-27T22:15:08.533
Modified: 2024-11-21T07:27:28.303
Link: CVE-2022-43978
No data.
OpenCVE Enrichment
No data.
EUVD