Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43978


There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.


Published

2023-01-27T22:15:08.533

Last Modified

2024-11-21T07:27:28.303

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pandorafms pandora_fms < 766 Yes

References