vendor:
Pandora FMS
by:
xistence
8,8
CVSS
HIGH
Command Injection
78
CWE
Product Name: Pandora FMS
Affected Version From: Pandora FMS 5.0RC1
Affected Version To: Pandora FMS 5.0RC1
Patch Exists: YES
Related CWE: CVE-2010-4258
CPE: 2.3:a:pandorafms:pandorafms
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
Command Injection in Pandora FMS
Pandora FMS versions 5.0RC1 and below are vulnerable to a command injection vulnerability in the "p" POST parameter of the Anytermd daemon used for the SSH/Telnet gateway on TCP port 8022/8023. This allows an unauthenticated attacker to execute arbitrary commands with the rights of the "pandora" user. Additionally, versions 4.1 and 5.0 RC1 fail to set a password for the "artica" user during installation to the harddrive, allowing an attacker to use the command injection vulnerability to "su" to the "artica" user and from there "sudo" to the "root" user as "sudo" won't ask for a password either.
Mitigation:
Users should upgrade to the latest version of Pandora FMS.