Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-34260 Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
Fixes

Solution

Fixed in v772


Workaround

No workaround given by the vendor.

History

Fri, 03 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-01-03T15:22:20.936Z

Reserved: 2023-05-19T08:29:18.021Z

Link: CVE-2023-2807

cve-icon Vulnrichment

Updated: 2024-08-02T06:33:05.503Z

cve-icon NVD

Status : Modified

Published: 2023-06-13T12:15:09.380

Modified: 2024-11-21T07:59:19.733

Link: CVE-2023-2807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.